Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-07-17
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

home/campaigns/npm/yzl520

// publisher campaign · npm

yzl520

All caught packages published by the yzl520 account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.

↗npmjs.com publisher↗pypi.org user
packages
3
distinct names
catch events
3
versions × names
blast
—
combined weekly downloads
active span
2026-05-19 → 2026-05-19
first → last catch

// publisher osint

Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.

activity on npm
  • packages on registry: 49
  • first publish: 2020-11-29
  • latest publish: 2026-07-13
  • active span: 2052d
same handle on other registries
  • npm /~yzl520: exists ↗
  • pypi /user/yzl520: exists ↗
  • github.com/yzl520: exists ↗
email domains
  • hotmail.com×3webmail
  • qq.com×3webmail
  • gmail.com×3webmail

// exfil path

what is read → where it ships
steals
  • ○ home dir
→
sends to

(no destination string extracted — payload may be dynamic / obfuscated)

Targets resolved from static-analysis flags; destinations extracted from the captured code excerpt. Full list + structured fields available in the IOC panel below.

// cross-publisher email signals

An email from this campaign also appears on caught packages under a different publisher account. Strong evidence that one operator runs both handles.

  • wzwahl36@qq.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by

// shared author identifiers

Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.

emails
  • luojiyin@hotmail.com— @lint-md/cli, @lint-md/core, @lint-md/parser
  • wzwahl36@qq.com— @lint-md/cli, @lint-md/core, @lint-md/parser
  • loveyzl1123@gmail.com— @lint-md/cli, @lint-md/core, @lint-md/parser
author names
  • hustcc— @lint-md/cli, @lint-md/core

// pattern footprint

Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.

  • ×1
  • ×1
  • ×1
  • ×1

// full activity on npm

Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.3/49 caught.

  • ●
    @ 2.2.2

    CLI tool to lint your markdown file for Chinese.

    2026-07-13
  • ●
    @ 2.1.5

    Core of lint-md which used to lint your markdown file for Chinese.

    2026-07-13
  • ●
    @ 0.1.2

    lint-md 的解析器,基于 remark 生态,将 Markdown 字符串转换成 AST

    2026-07-02
  • ○
    @attachments/babel-plugin-i18n@ 0.4.0

    > TODO: description

    2023-04-09

// packages in this campaign

3 distinct · newest first
  • ↳ author:yuzhanglong<loveyzl1123@gmail.com>maintainers: luojiyin <luojiyin@hotmail.com>, atool <wzwahl36@qq.com>, yzl520 <loveyzl1123@gmail.com>↗ registry
  • ↳ author:hustccmaintainers: luojiyin <luojiyin@hotmail.com>, atool <wzwahl36@qq.com>, yzl520 <loveyzl1123@gmail.com>↗ registry
  • ↳ author:hustccmaintainers: luojiyin <luojiyin@hotmail.com>, atool <wzwahl36@qq.com>, yzl520 <loveyzl1123@gmail.com>↗ registry
  • ○
    @attachments/assets@ 0.4.0

    common resource tool packages, such as the CSS and project templates

    2023-04-09
  • ○
    @attachments/proxy@ 0.4.0

    proxy server for front-end developers

    2023-04-09
  • ○
    @attachments/i18n@ 0.4.0

    > TODO: description

    2023-04-09
  • ○
    @attachments/hooks@ 0.4.0
    2023-04-09
  • ○
    @attachments/i18n-webpack-plugin@ 0.4.0

    > TODO: description

    2023-04-09
  • ○
    @attachments/eslint-config@ 0.4.0

    useful eslint config

    2023-04-09
  • ○
    @attachments/github-trending@ 0.4.0

    github trending API wrapper

    2023-04-09
  • ○
    @attachments/utils@ 0.4.0

    useful front-end development tool library

    2023-04-09
  • ○
    dependency-packager@ 0.0.0
    2023-04-01
  • ○
    @attachments/plop-plus@ 0.3.1

    > TODO: add description

    2022-10-29
  • ○
    @url-scheme/shared@ 0.0.0

    > TODO: add description

    2022-06-16
  • ○
    @attachments/eslint-plugin@ 0.2.2

    useful eslint-plugin

    2022-05-14
  • ○
    @url-scheme/core@ 0.0.1

    > TODO: add description

    2022-05-02
  • ○
    @attachments/monitor-sdk-browser@ 0.1.26

    TODO

    2021-12-15
  • ○
    @mf-lite/cli@ 0.1.9

    A scaffold for quickly creating base applications or micro-front-end applications from the command line

    2021-12-11
  • ○
    @mf-lite/core@ 0.1.9

    core library for mf-lite

    2021-12-11
  • ○
    find-my-code@ 0.0.0

    > TODO: add description

    2021-11-19
  • ○
    @attachments/monitor@ 0.1.19

    TODO

    2021-10-23
  • ○
    @mf-lite/module-federation-toolkits@ 0.0.1

    > TODO: description

    2021-10-18
  • ○
    @attachments/module-federation-toolkits@ 0.1.12

    > TODO: description

    2021-10-17
  • ○
    antd-onboarding@ 0.1.0

    <h1 align="center"> <b>antd-onboarding</b> </h1>

    2021-09-21
  • ○
    @attachments/i18n-babel-plugin@ 0.0.2

    > TODO: description

    2021-08-18
  • ○
    @attachments/serendipity-plugin-eslint@ 0.1.18

    ## 概述

    2021-06-15
  • ○
    @attachments/serendipity-plugin-babel@ 0.1.16

    babel plugin

    2021-06-14
  • ○
    @attachments/serendipity-scripts@ 0.1.16

    > TODO: description

    2021-06-14
  • ○
    @attachments/serendipity-plugin-typescript@ 0.1.16
    2021-06-14
  • ○
    @attachments/serendipity@ 0.1.16

    > cli manager for serendipity

    2021-06-14
  • ○
    @attachments/serendipity-plugin-react@ 0.1.16

    ## 概述

    2021-06-14
  • ○
    @attachments/serendipity-plugin-init@ 0.1.16

    ## 概述

    2021-06-14
  • ○
    @attachments/serendipity-core@ 0.1.16

    > TODO: description

    2021-06-14
  • ○
    @attachments/serendipity-webpack-plugin@ 0.1.16
    2021-06-14
  • ○
    @attachments/serendipity-public@ 0.1.16
    2021-06-14
  • ○
    limerence@ 0.0.1

    > TODO: description

    2021-04-27
  • ○
    @jest-electron/runner@ 0.0.3

    > TODO: description

    2021-03-31
  • ○
    @jest-electron/core@ 0.0.3

    > TODO: description

    2021-03-31
  • ○
    @lint-md/eslint-plugin@ 0.1.0

    :sunglasses: 基于 @lint-md,提供 eslint-plugin,让 lint-md 玩家得到愉悦的文档编写体验。

    2021-03-30
  • ○
    node-require-webpack-plugin@ 0.1.1

    为 node.js 环境下的 webpack 打包结果提供动态 require 支持。

    2021-03-30
  • ○
    redamancy@ 0.0.4
    2021-03-27
  • ○
    jest-electron-test@ 0.1.14

    Easiest way to run jest unit test cases in electron.

    2021-03-27
  • ○
    @attachments/serendipity-workflows@ 0.1.9
    2021-03-26
  • ○
    @lint-md/ast-plugin@ 1.0.1

    The simplest abstract syntax tree walker.

    2021-03-23
  • ○
    serendipity-core@ 0.1.7

    > TODO: description

    2021-03-14
  • ○
    eslint-plugin-lint-md@ 0.0.3

    依靠各个 IDE 对 eslint 不错的支持,让 lint-md 玩家也能得到愉悦的文档编写体验。

    2021-03-09
  • ○
    @attachments/serendipity-service-react@ 0.1.0
    2021-02-18
  • ○
    html-externals-webpack-plugin@ 0.0.2

    webpack plugin for externals

    2020-11-29
  • npm/@antv/l7
    lzxue
    npm/@antv/l7-maps
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-layers
    lzxue
    npm/@antv/l7-component
    lzxue
    install-path-npm-publish
    child-process-spawn
    public-github-push
    reads-homedir
    @lint-md/cli
    @lint-md/core
    @lint-md/parser
    AUTO-PUBLISHED/npm/2022-11-05/MAL-2026-4125

    @lint-md/parser@0.0.14

    by yzl520

    lint-md 的解析器,基于 remark 生态,将 Markdown 字符串转换成 AST

    → sends tohttps://github.com/lint-md

    → No suspicious destination, no remote-exec shape — 3 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    size
    1.9 MB
    versions
    15
    AUTO-PUBLISHED/npm/2023-07-12/MAL-2026-4124

    @lint-md/core@2.0.0

    by yzl520

    Core of lint-md which used to lint your markdown file for Chinese.

    install-path-npm-publishchild-process-spawn

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    2
    size
    208.1 KB
    versions
    23
    AUTO-PUBLISHED/npm/2023-07-12/MAL-2026-4123

    @lint-md/cli@2.0.0

    by yzl520

    CLI tool to lint your markdown file for Chinese.

    public-github-pushreads-homedir

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    2
    size
    68.4 KB
    versions
    18