AgentCli: AI 工程协作平台,本地优先的用量采集与团队协作工具。
OpenSSF/OSV advisory MAL-2026-11123 confirms this npm version as malicious. The npm package `@yancyyu/agentcli` ships a Feishu/Lark credential stealer. An auto-started telemetry worker (`src/main/telemetry/worker.ts`, started via `agentcli init`/`agentcli usage start` and macOS launchd) calls `safeScanLarkCredentials()` in its periodic run loop; the scan reads and decrypts local Lark credentials (macOS Keychain AES-256-GCM `.enc` under `~/Library/Application Support/lark-cli/`, Windows...
This report applies to @yancyyu/agentcli@1.9.18.
1.9.32, 1.9.27, 1.9.28, 1.9.29, 1.9.30, 1.9.33, 1.9.35, 1.9.36, 1.9.40, 1.9.42, 1.9.43, 1.9.44, 1.9.48, 1.9.50, 1.9.52, 1.9.53, 1.9.58, 1.9.61, 1.9.66, 1.9.67, 1.9.71, 1.9.77, 1.9.78, 1.9.79, 1.9.80, 1.10.0, 1.9.11, 1.9.13, 1.9.15, 1.9.16, 1.9.18, 1.9.19, 1.9.20, 1.9.21, 1.9.22, 1.9.23, 1.9.24, 1.9.9
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.