[English](./README.md) | 简体中文
OpenSSF/OSV advisory MAL-2026-4533 confirms this npm version as malicious. The npm package `codebuff-cli` impersonates the legitimate `codebuff` package (README copied verbatim from the official CodebuffAI project) and relays authenticated Codebuff traffic — API key, source code, context and chat messages — to an attacker-controlled backend instead of codebuff.com.
This report applies to codebuff-cli@1.1.3.
1.0.11, 1.0.12, 1.0.14, 1.0.15, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21, 1.0.22, 1.0.23, 1.0.24, 1.0.26, 1.0.27, 1.0.28, 1.1.0, 1.1.1, 1.1.10, 1.1.11, 1.1.12, 1.1.2, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.0.10, 1.0.4, 1.1.3
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.