Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-08-19
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

home/campaigns/npm/mercmobily

// publisher campaign · npm

mercmobily

All caught packages published by the mercmobily account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.

↗npmjs.com publisher↗pypi.org user
packages
2
distinct names
catch events
2
versions × names
blast
—
combined weekly downloads
active span
2026-05-20 → 2026-05-20
first → last catch

// publisher osint

Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.

activity on npm
  • packages on registry: 88
  • first publish: 2016-04-15
  • latest publish: 2026-08-17
  • active span: 3776d
same handle on other registries
  • npm /~mercmobily: exists ↗
  • pypi /user/mercmobily: exists ↗
  • github.com/mercmobily: exists ↗
email domains
  • gmail.com×3webmail
  • ryanclark.me×1
  • contextaware.com.br×1

// shared author identifiers

Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.

emails
  • tonymobily@gmail.com— reducs, routify
author names
  • tony mobily— reducs, routify

// pattern footprint

Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.

  • ×1

// full activity on npm

Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.2/88 caught.

  • ○
    genesis-compiler@ 1.2.9

    An agent-independent prompt, multi-language code-index, cleanup, and verification companion with optional Codex hooks.

    2026-08-17
  • ○
    genesis-stack@ 1.0.0

    The optional curated technology Stack catalog for Genesis projects.

    2026-08-17
  • ○
    @jskit-ai/workspaces-web@ 0.1.141

    Workspace web module: workspace selector, tools widget, workspace surfaces, members UI, and settings hosts.

    2026-08-16
  • ○

// packages in this campaign

2 distinct · newest first
  • ↳ author:Tony Mobilymaintainers: mercmobily <tonymobily@gmail.com>↗ registry
  • ↳ author:Tony Mobilymaintainers: mercmobily <tonymobily@gmail.com>, ryanclark <ryan@ryanclark.me>, freudflintstone <raphael.mattos@contextaware.com.br>, ghostsos <ghostdevbusiness@gmail.com>↗ registry
@jskit-ai/google-rewarded-web@ 0.1.98

Google rewarded client runtime with a fullscreen gate host and GPT orchestration.

2026-08-16
  • ○
    @jskit-ai/google-rewarded-core@ 0.1.98

    Google rewarded workflow runtime plus internal CRUD providers for rules, provider configs, watch sessions, and unlock receipts.

    2026-08-16
  • ○
    @jskit-ai/workspaces-core@ 0.1.140

    Workspace tenancy runtime plus HTTP routes, role catalog, and workspace config scaffolding.

    2026-08-16
  • ○
    @jskit-ai/users-web@ 0.1.180

    Users web module with account, profile, and user-specific shell UI.

    2026-08-16
  • ○
    @jskit-ai/console-web@ 0.1.130

    Authenticated console surface scaffold and surface policy wiring.

    2026-08-16
  • ○
    @jskit-ai/console-core@ 0.1.125

    Console runtime: console settings schema, bootstrap flags, actions, and HTTP routes.

    2026-08-16
  • ○
    @jskit-ai/users-core@ 0.1.175

    Users/account runtime plus HTTP routes for account features.

    2026-08-16
  • ○
    @jskit-ai/uploads-image-web@ 0.1.137

    Reusable client-side image upload runtime with pre-upload image editing.

    2026-08-16
  • ○
    @jskit-ai/uploads-runtime@ 0.1.137

    Reusable upload runtime primitives for multipart parsing, policy validation, and blob storage.

    2026-08-16
  • ○
    @jskit-ai/storage-runtime@ 0.1.159
    2026-08-16
  • ○
    @jskit-ai/assistant-runtime@ 0.1.133

    Capability-based assistant runtime with per-surface chat, transcripts, settings, and action tools.

    2026-08-16
  • ○
    @jskit-ai/http-web@ 0.1.7

    Neutral Vue request, command, resource, and CRUD UI runtime for JSKIT web applications.

    2026-08-16
  • ○
    @jskit-ai/realtime@ 0.1.159

    Thin, generic realtime runtime wrappers for socket.io server and client.

    2026-08-16
  • ○
    @jskit-ai/mobile-capacitor@ 0.1.97

    Thin Capacitor client integration for JSKIT mobile-shell launch routing and auth callback completion.

    2026-08-16
  • ○
    @jskit-ai/auth-web@ 0.1.162

    Auth web module: Fastify auth routes plus web login/sign-out scaffolds.

    2026-08-16
  • ○
    @jskit-ai/shell-web@ 0.1.166

    Web shell layout runtime with outlet-based placement contributions.

    2026-08-16
  • ○
    @jskit-ai/crud-core@ 0.1.173

    Shared server-side CRUD service, repository, route, and query helpers.

    2026-08-16
  • ○
    @jskit-ai/json-rest-api-core@ 0.1.106

    Shared internal json-rest-api host runtime with autofilter, query-projection, and row-policy support.

    2026-08-16
  • ○
    @jskit-ai/assistant-core@ 0.1.138

    Reusable assistant client/server/shared primitives without surface-specific routes or settings ownership.

    2026-08-16
  • ○
    @jskit-ai/resource-crud-core@ 0.1.104

    Shared CRUD resource, field, lookup, filter, and namespace contracts.

    2026-08-16
  • ○
    @jskit-ai/resource-core@ 0.1.104

    Generic resource-definition helpers and schema-definition normalization.

    2026-08-16
  • ○
    @jskit-ai/http-runtime@ 0.1.160
    2026-08-16
  • ○
    @jskit-ai/database-runtime-postgres@ 0.1.159
    2026-08-16
  • ○
    @jskit-ai/database-runtime-mysql@ 0.1.160
    2026-08-16
  • ○
    @jskit-ai/auth-provider-local-db-core@ 0.1.54

    Database-backed local auth storage backend for JSKIT local auth.

    2026-08-16
  • ○
    @jskit-ai/database-runtime@ 0.1.162
    2026-08-16
  • ○
    @jskit-ai/auth-provider-supabase-core@ 0.1.159
    2026-08-16
  • ○
    @jskit-ai/auth-provider-local-core@ 0.1.63

    Local auth provider with a file backend default and no database requirement.

    2026-08-16
  • ○
    @jskit-ai/auth-core@ 0.1.160
    2026-08-16
  • ○
    @jskit-ai/kernel@ 0.1.162

    Internal JSKIT framework runtime package.

    2026-08-16
  • ○
    @jskit-ai/jskit-catalog@ 0.1.187

    Published metadata catalog for JSKIT package metadata.

    2026-08-16
  • ○
    @jskit-ai/config-eslint@ 0.1.159

    Shared flat ESLint presets for JSKIT projects.

    2026-08-16
  • ○
    @jskit-ai/agent-docs@ 0.1.134

    Distributed JSKIT agent references, prompts, guides, and generated reference maps.

    2026-08-16
  • ○
    @jskit-ai/assistant@ 0.1.167

    Install assistant runtime/config for one surface and scaffold assistant pages at explicit target files.

    2026-08-14
  • ○
    @jskit-ai/ui-generator@ 0.1.141

    Create non-CRUD pages, reusable UI elements, and subpage hosts.

    2026-08-14
  • ○
    @jskit-ai/crud-server-generator@ 0.1.172

    CRUD server generator with routes, actions, and persistence scaffolding.

    2026-08-14
  • ○
    @jskit-ai/create-app@ 0.1.182

    Scaffold JSKIT app shells.

    2026-08-14
  • ○
    @jskit-ai/jskit-cli@ 0.2.190

    Bundle and package orchestration CLI for JSKIT apps.

    2026-08-14
  • ○
    @jskit-ai/crud-ui-generator@ 0.1.143

    Generate CRUD route trees from resource validators at an explicit route root relative to src/pages/.

    2026-08-14
  • ○
    @jskit-ai/feature-server-generator@ 0.1.101

    Scaffold substantial non-CRUD server feature packages with provider, actions, service, and optional persistence seams.

    2026-08-14
  • ○
    json-rest-schema@ 1.0.17

    A flexible and extensible schema validation library for JavaScript objects, designed for REST APIs and beyond. Features include type casting, data transformation, and a pluggable architecture for custom rules.

    2026-08-12
  • ○
    vibe64@ 0.1.24

    Run Vibe64 against the current project.

    2026-07-30
  • ○
    json-rest-api@ 1.0.27

    REST API plugin for hooked-api with JSON:API compliance

    2026-07-29
  • ○
    tpe@ 1.0.29

    The Platform Elements

    2026-07-17
  • ○
    @vibe-armor/run@ 0.1.21

    Run AI Studio against the current project.

    2026-05-19
  • ○
    @jskit-ai/crud@ 0.1.25
    2026-03-23
  • ○
    jskit-vue@ 0.0.33

    JS Kit repository

    2025-11-28
  • ○
    jskit-auth-server@ 0.3.3

    Reusable authentication helpers for json-rest-api or plain Express apps

    2025-11-14
  • ○
    scaffoldizer@ 0.0.29

    Modular scaffold creation

    2025-11-14
  • ○
    jskit-auth-client@ 0.6.2

    Reusable Vue 3 authentication client for RemindJS auth backends.

    2025-10-14
  • ○
    hooked-api@ 1.0.24

    Hooked API allows you to create API calls that can be extended with hooks and variables. For example you can create a library that connects to a database, and allow users to provide hooks to manipulate the lifecycle of a call.

    2025-10-14
  • ○
    route-trie-esm@ 3.0.4

    A minimal and powerful trie based url path router for Node.js.

    2025-10-14
  • ○
    js-kit@ 0.0.14

    JS Kit repository

    2025-10-14
  • ○
    tpe-material@ 1.0.13

    The Platform Elements - Material Theme

    2025-10-13
  • ○
    use-back-button@ 1.0.0

    A Vue 3 composable to track back navigation in SPAs using Vue Router

    2025-06-11
  • ○
    historify@ 1.0.4

    Browser istory management for single page applications

    2024-06-27
  • ○
    js-interpreter-esm@ 1.0.3

    Neil Fraser's official JS-Interpreter

    2024-03-25
  • ○
    js-interpreter-npm@ 1.0.10

    NPM package for Neil Fraser's JS-Interpreter

    2024-03-22
  • ○
    jsonreststores-mysql@ 2.0.33

    Mixin to implement MySql calls for jsonreststores

    2024-01-26
  • ○
    routify-lit@ 2.0.3

    The most powerful client-side routing in the west

    2024-01-21
  • ○
    jsonreststores@ 2.0.19

    A module to create full Json REST stores in minutes

    2023-12-30
  • ●
    routify@ 2.0.1

    The most powerful client-side routing in the west

    2023-07-27
  • ○
    docco-next@ 0.9.14

    Literate programming parser

    2022-12-08
  • ○
    ejs4b@ 3.1.63

    EJS available for browsers as ES6 module

    2022-08-26
  • ○
    simpleschema@ 2.0.7

    The simplest, most extendible schema class you will ever come across

    2022-04-05
  • ○
    spa-data-loader@ 1.0.8

    A data loader for SPA (Single Page Applications)

    2022-02-20
  • ○
    web-sites-common@ 1.0.2

    Common properties for JS-KIT related web sites

    2022-02-20
  • ○
    eslint-plugin-literate-comments@ 1.0.3

    Plugin to allow col-1 literate comments in a file

    2022-02-20
  • ○
    spa-fetch@ 1.0.3

    Global fetch for Single Page Applications

    2022-02-17
  • ○
    best-webdriver@ 1.2.3

    Best webdriver around using async/await, simplified down-to-earth API, easy to debug, 1:1 matching with the webdriver API. You will be testing in 20 minutes, not 20 hours

    2021-11-28
  • ○
    tpe-demo@ 1.0.1
    2021-09-07
  • ○
    es6-dev-server@ 0.0.10

    Serve ES6 modules ensuring node resolution via the node algorithm. Express middleware and full server

    2021-09-05
  • ○
    lit-kit@ 1.0.0

    Scaffolding for lit applications

    2021-07-19
  • ○
    scaffoldizer-example@ 0.0.1

    An example scaffold

    2020-08-18
  • ○
    jsonreststores2@ 1.1.48

    A module to create full Json REST stores in minutes

    2020-02-05
  • ●
    reducs@ 0.0.10

    A sane implementation of Redux

    2019-10-30
  • ○
    simpleschema2@ 1.1.20

    The simplest, most extendible schema class you will ever come across

    2019-10-12
  • ○
    allhttperrors@ 0.4.2

    A module to create flexible, powerful Error objects based on HTTP responses

    2018-04-13
  • ○
    simpledblayer-mongo@ 0.3.57

    MongoDB layer for simpledblayer

    2017-12-20
  • ○
    hotplate@ 0.3.120

    Hotplate SaaS development framework

    2017-12-05
  • ○
    simpledblayer@ 0.3.38

    Simple, generic, no fuss DB layer for NodeJS

    2017-10-06
  • ○
    naps@ 0.1.7

    A multi-purpose node app manager

    2017-09-14
  • ○
    ryver@ 0.1.19

    Static web site generator

    2017-03-31
  • ○
    simpledeclare@ 0.3.29

    A simple implementation of declare() to have Javascript (single and multiple) inheritance in a very elegant, close-to-metal way

    2016-11-03
  • ○
    simpledblayer-tingo@ 0.3.29

    TingoDB layer for simpledblayer

    2016-04-15
  • public-github-push
    AUTO-PUBLISHED/npm/2019-10-27

    reducs@1.0.1

    by mercmobily

    A sane implementation of Redux

    → No suspicious destination, no remote-exec shape — 2 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    87
    size
    970 B
    versions
    5
    AUTO-PUBLISHED/npm/2020-02-19

    routify@1.0.0

    by mercmobily

    The most powerful client-side routing in the west

    → sends tohttps://github.com/mobilyenterprises/routify.git
    public-github-push

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    87
    patterns
    1
    size
    45.4 KB
    versions
    32