Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-07-17
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

home/campaigns/npm/jiulingyun

// publisher campaign · npm

jiulingyun

All caught packages published by the jiulingyun account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.

↗npmjs.com publisher↗pypi.org user
packages
6
distinct names
catch events
6
versions × names
blast
135/wk
combined weekly downloads
active span
2026-05-19 → 2026-05-19
first → last catch

// publisher osint

Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.

activity on npm
  • packages on registry: 9
  • first publish: 2026-01-27
  • latest publish: 2026-05-19
  • active span: 111d
same handle on other registries
  • npm /~jiulingyun: exists ↗
  • pypi /user/jiulingyun: exists ↗
  • github.com/jiulingyun: not found
email domains
  • jiulingyun.cn×6

// exfil path

what is read → where it ships
steals
  • ● AI API keys
  • ○ home dir
→
sends to

(no destination string extracted — payload may be dynamic / obfuscated)

Targets resolved from static-analysis flags; destinations extracted from the captured code excerpt. Full list + structured fields available in the IOC panel below.

// shared author identifiers

Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.

emails
  • yangmingfeng@jiulingyun.cn— openclaw-cn, @starmind/collector-cli, @openclaw-cn/toutiao-ops, @openclaw-cn/feishu, @openclaw-cn/cli, @openclaw-cn/libsignal

// pattern footprint

Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.

  • ×2
  • ×2
  • ×2
  • ×2
  • ×2
  • ×1
  • ×1
  • ×1
  • ×1

// full activity on npm

Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.5/9 caught.

  • ○
    @starmind/ops-cli@ 0.1.0

    多多运营后台 CLI — 销售/库存/利润/仓储费查询、主数据管理,通过 OPS_JWT 与云端 API 交互

    2026-05-19
  • ●
    @ 0.2.10

    拼多多采集 CLI — 无需直连数据库,通过 WORKER_JWT_SECRET 与云端 API 交互

    2026-05-18
  • ●
    @ 1.1.4

    今日头条创作者平台运营自动化 CLI — 支持多账号管理、文章/视频/微头条发布、评论管理、数据分析、创作灵感获取

    2026-04-08
  • ●
    @ 1.3.1

    The official CLI for OpenClaw-CN Agent ecosystem

    2026-03-28

// packages in this campaign

6 distinct · newest first
  • ↳ author:maintainers: jiulingyun <yangmingfeng@jiulingyun.cn>↗ registry
  • ↳ author:maintainers: jiulingyun <yangmingfeng@jiulingyun.cn>↗ registry
  • ↳ author:OpenClaw-CNmaintainers: jiulingyun <yangmingfeng@jiulingyun.cn>↗ registry
  • ↳ author:maintainers: jiulingyun <yangmingfeng@jiulingyun.cn>↗ registry
  • ↳ author:maintainers: jiulingyun <yangmingfeng@jiulingyun.cn>↗ registry
  • ↳ author:maintainers: jiulingyun <yangmingfeng@jiulingyun.cn>↗ registry
  • ○
    @openclaw-cn/baileys@ 7.0.0-rc.9

    A WebSockets library for interacting with WhatsApp Web

    2026-02-04
  • ●
    openclaw-cn@ 2026.2.5

    Openclaw 中文版 - WhatsApp gateway CLI (Baileys web) with Pi RPC agent

    2026-02-03
  • ●
    @openclaw-cn/libsignal@ 2.0.1

    Signal protocol implementation for Node.js (fork for openclaw-cn)

    2026-02-03
  • ○
    moltbot-cn@ 2026.1.24-cn.3

    Moltbot 中文版 - WhatsApp gateway CLI (Baileys web) with Pi RPC agent

    2026-01-28
  • ○
    clawdbot-cn@ 2026.1.24-cn.2

    Clawdbot 中文版 - WhatsApp gateway CLI (Baileys web) with Pi RPC agent

    2026-01-27
  • reads-env-vars
    base64-decode
    child-process-spawn
    public-github-push
    reads-homedir
    archive-then-upload
    reads-ai-api-keys
    py-urllib-request
    mcp-skill-bundle
    @starmind/collector-cli
    @openclaw-cn/toutiao-ops
    @openclaw-cn/cli
    AUTO-PUBLISHED/npm/2026-03-29/MAL-2026-3847

    openclaw-cn@0.2.0

    by jiulingyun

    Openclaw 中文版 - WhatsApp gateway CLI (Baileys web) with Pi RPC agent

    steals →AI API keys→ sends tohttps://api.openai.com/v1/audio/transcriptions
    archive-then-uploadreads-ai-api-keysreads-env-varsbase64-decodepy-urllib-requestchild-process-spawnpublic-github-pushreads-homedir+1

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    9
    size
    30.4 MB
    versions
    47
    AUTO-PUBLISHED/npm/2026-05-18/MAL-2026-3845

    @starmind/collector-cli@0.2.10

    by jiulingyun

    拼多多采集 CLI — 无需直连数据库,通过 WORKER_JWT_SECRET 与云端 API 交互

    → sends tohttps://registry.npmjs.org/

    → No suspicious destination, no remote-exec shape — 3 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    size
    235.2 KB
    versions
    11
    AUTO-PUBLISHED/npm/2026-04-08/MAL-2026-3844

    @openclaw-cn/toutiao-ops@1.1.4

    by jiulingyun

    今日头条创作者平台运营自动化 CLI — 支持多账号管理、文章/视频/微头条发布、评论管理、数据分析、创作灵感获取

    → sends tohttps://mp.toutiao.com/profile_v4/activity/task-list
    child-process-spawn

    → No suspicious destination, no remote-exec shape — 2 other host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    1
    size
    93.2 KB
    versions
    5
    AUTO-PUBLISHED/npm/2026-02-03/MAL-2026-3843

    @openclaw-cn/libsignal@2.0.1

    by jiulingyun

    Signal protocol implementation for Node.js (fork for openclaw-cn)

    base64-decode

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    1
    size
    126.8 KB
    versions
    1
    AUTO-PUBLISHED/npm/2026-03-07/MAL-2026-3842

    @openclaw-cn/feishu@0.1.11

    by jiulingyun

    Feishu (Larksuite) channel plugin for OpenClaw Chinese

    → sends togithub.com · https://github.com/openclaw/openclaw-cn/tree/main/extens…
    public-github-push

    → No suspicious destination, no remote-exec shape — 2 known-vendor host(s).

    weekly
    135
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    1
    size
    674.7 KB
    versions
    6
    AUTO-PUBLISHED/npm/2026-03-28/MAL-2026-3841

    @openclaw-cn/cli@1.3.1

    by jiulingyun

    The official CLI for OpenClaw-CN Agent ecosystem

    → sends tohttps://backend.clawd.org.cn/api
    reads-env-varsreads-homedir

    → No suspicious destination, no remote-exec shape — 1 other host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    2
    size
    74.4 KB
    versions
    24