Cremit
/incidentsfield log
탐지캠페인유출지패턴LLM사고 사례방법론
↺rss↗cremit.io

incidents.cremit.io

실제 발생한 비인간 식별자(NHI) 크리덴셜 유출 사고를 정리한 인덱스. 운영: Cremit

둘러보기

  • 전체 사고
  • npm 공급망
  • CI/CD 침해
  • 방법론

구독

  • RSS 피드
  • @cremit_io
  • GitHub
// 상태
모니터 가동중
// 빌드
2026-07-17
// 출처
cremit · 서울, 대한민국
// 라이선스
CC BY 4.0

© 2026 Cremit. 출처 표시 시 자유롭게 재사용 가능.

home/campaigns/npm/mercmobily

// publisher 캠페인 · npm

mercmobily

npm의 mercmobily 계정이 publish한 catch 패키지 전체와, registry가 현재 노출하는 author·maintainer 정보. 같은 이메일이나 이름이 여러 패키지에 걸쳐 등장하면, 한 명이 여러 throwaway 계정을 운영한다는 강한 증거입니다.

↗npmjs.com publisher↗pypi.org user
패키지
2
고유 이름 수
탐지 이벤트
2
버전 × 이름
blast
—
주간 다운로드 합계
활동 기간
2026-05-20 → 2026-05-20
최초 → 최근 탐지

// publisher OSINT

이 계정 자체에 대한 시그널. 활동 기간이 짧으면 throwaway 가능성이 큽니다. 이메일 도메인을 보면 단발 webmail인지 진짜 조직 메일인지 한눈에 갈리고, 같은 핸들이 여러 registry에 있으면 같은 운영자라고 볼 강한 근거가 됩니다. GitHub 링크가 잡히면 실명 식별까지 곧장 이어집니다.

npm 활동
  • registry 패키지 수: 85
  • 최초 publish: 2016-04-15
  • 최근 publish: 2026-07-17
  • 활동 기간: 3745일
다른 registry의 같은 핸들
  • npm /~mercmobily: 존재함 ↗
  • pypi /user/mercmobily: 존재함 ↗
  • github.com/mercmobily: 존재함 ↗
이메일 도메인
  • gmail.com×3webmail
  • ryanclark.me×1
  • contextaware.com.br×1

// 공유 author 식별자

같은 이메일·이름이 캠페인 안 여러 패키지에 등장하는 경우. publisher 계정 외에 별도로 잡히는 직접적인 attribution 증거입니다.

emails
  • tonymobily@gmail.com— reducs, routify
author names
  • tony mobily— reducs, routify

// 패턴 풋프린트

캠페인 전반에서 어떤 정적 분석 플래그가 얼마나 자주 매칭됐는지. "이 캠페인이 결국 어떤 종류의 stealer인가"에 대한 요약 답.

  • ×1

// npm에 등록된 전체 활동

이 계정이 지금 registry에 올려둔 모든 패키지 (최신순). ● Cremit 파이프라인이 catch · ○ 아직 미검출.2/85 catch.

  • ○
    @jskit-ai/crud-server-generator@ 0.1.125
    2026-07-17
  • ○
    @jskit-ai/crud-ui-generator@ 0.1.100

    Generate CRUD route trees from an explicit route root relative to `src/pages/...`.

    2026-07-17
  • ○
    @jskit-ai/crud-core@ 0.1.125
    2026-07-17
  • ○
    @jskit-ai/workspaces-web@ 0.1.94
    2026-07-17

// 이 캠페인의 패키지

고유 이름 2개 · 최신순
  • ↳ author:Tony Mobilymaintainers: mercmobily <tonymobily@gmail.com>↗ registry
  • ↳ author:Tony Mobilymaintainers: mercmobily <tonymobily@gmail.com>, ryanclark <ryan@ryanclark.me>, freudflintstone <raphael.mattos@contextaware.com.br>, ghostsos <ghostdevbusiness@gmail.com>↗ registry
  • ○
    @jskit-ai/assistant-runtime@ 0.1.88
    2026-07-17
  • ○
    @jskit-ai/console-web@ 0.1.85
    2026-07-17
  • ○
    @jskit-ai/create-app@ 0.1.128

    Scaffold JSKIT app shells.

    2026-07-17
  • ○
    @jskit-ai/users-web@ 0.1.133
    2026-07-17
  • ○
    @jskit-ai/workspaces-core@ 0.1.93
    2026-07-17
  • ○
    @jskit-ai/console-core@ 0.1.80
    2026-07-17
  • ○
    @jskit-ai/assistant-core@ 0.1.93
    2026-07-17
  • ○
    @jskit-ai/auth-provider-local-db-core@ 0.1.10
    2026-07-17
  • ○
    @jskit-ai/jskit-cli@ 0.2.131

    Bundle and package orchestration CLI for JSKIT apps.

    2026-07-17
  • ○
    @jskit-ai/users-core@ 0.1.127
    2026-07-17
  • ○
    @jskit-ai/ui-generator@ 0.1.100

    Generate app-local UI pages, page links, placed elements, and routed subpage hosts for JSKIT apps.

    2026-07-17
  • ○
    @jskit-ai/auth-web@ 0.1.118
    2026-07-17
  • ○
    @jskit-ai/auth-provider-supabase-core@ 0.1.116
    2026-07-17
  • ○
    @jskit-ai/auth-provider-local-core@ 0.1.18
    2026-07-17
  • ○
    @jskit-ai/database-runtime-mysql@ 0.1.117
    2026-07-17
  • ○
    @jskit-ai/database-runtime-postgres@ 0.1.116
    2026-07-17
  • ○
    @jskit-ai/uploads-image-web@ 0.1.95
    2026-07-17
  • ○
    @jskit-ai/resource-crud-core@ 0.1.62
    2026-07-17
  • ○
    @jskit-ai/shell-web@ 0.1.117
    2026-07-17
  • ○
    @jskit-ai/http-runtime@ 0.1.117
    2026-07-17
  • ○
    @jskit-ai/auth-core@ 0.1.116
    2026-07-17
  • ○
    @jskit-ai/database-runtime@ 0.1.118
    2026-07-17
  • ○
    @jskit-ai/realtime@ 0.1.116
    2026-07-17
  • ○
    @jskit-ai/mobile-capacitor@ 0.1.54

    Stage 1 Android mobile-shell support for JSKIT.

    2026-07-17
  • ○
    @jskit-ai/resource-core@ 0.1.62
    2026-07-17
  • ○
    @jskit-ai/uploads-runtime@ 0.1.95
    2026-07-17
  • ○
    @jskit-ai/json-rest-api-core@ 0.1.62
    2026-07-17
  • ○
    @jskit-ai/assistant@ 0.1.126

    Install assistant runtime/config for one surface, then scaffold assistant pages at explicit page files.

    2026-07-17
  • ○
    @jskit-ai/storage-runtime@ 0.1.116
    2026-07-17
  • ○
    @jskit-ai/agent-docs@ 0.1.80

    Distributed JSKIT agent references, prompts, guides, and generated reference maps.

    2026-07-17
  • ○
    @jskit-ai/kernel@ 0.1.119

    Internal JSKIT framework runtime package.

    2026-07-17
  • ○
    @jskit-ai/google-rewarded-core@ 0.1.54

    Server runtime for Google rewarded unlock gates.

    2026-07-17
  • ○
    @jskit-ai/google-rewarded-web@ 0.1.54

    Client runtime package for Google rewarded unlock gates.

    2026-07-17
  • ○
    @jskit-ai/feature-server-generator@ 0.1.60
    2026-07-17
  • ○
    @jskit-ai/config-eslint@ 0.1.116

    Shared flat ESLint presets for JSKIT projects.

    2026-07-17
  • ○
    @jskit-ai/jskit-catalog@ 0.1.126

    Published metadata catalog for JSKIT package descriptors.

    2026-07-17
  • ○
    vibe64@ 0.1.22

    Run Vibe64 against the current project.

    2026-05-30
  • ○
    @vibe-armor/run@ 0.1.21

    Run AI Studio against the current project.

    2026-05-19
  • ○
    json-rest-schema@ 1.0.16

    A flexible and extensible schema validation library for JavaScript objects, designed for REST APIs and beyond. Features include type casting, data transformation, and a pluggable architecture for custom rules.

    2026-05-19
  • ○
    json-rest-api@ 1.0.24

    REST API plugin for hooked-api with JSON:API compliance

    2026-05-01
  • ○
    @jskit-ai/crud@ 0.1.25
    2026-03-23
  • ○
    jskit-vue@ 0.0.33

    JS Kit repository

    2025-11-28
  • ○
    jskit-auth-server@ 0.3.3

    Reusable authentication helpers for json-rest-api or plain Express apps

    2025-11-14
  • ○
    scaffoldizer@ 0.0.29

    Modular scaffold creation

    2025-11-14
  • ○
    jskit-auth-client@ 0.6.2

    Reusable Vue 3 authentication client for RemindJS auth backends.

    2025-10-14
  • ○
    hooked-api@ 1.0.24

    Hooked API allows you to create API calls that can be extended with hooks and variables. For example you can create a library that connects to a database, and allow users to provide hooks to manipulate the lifecycle of a call.

    2025-10-14
  • ○
    route-trie-esm@ 3.0.4

    A minimal and powerful trie based url path router for Node.js.

    2025-10-14
  • ○
    js-kit@ 0.0.14

    JS Kit repository

    2025-10-14
  • ○
    tpe-material@ 1.0.13

    The Platform Elements - Material Theme

    2025-10-13
  • ○
    tpe@ 1.0.28

    The Platform Elements

    2025-10-13
  • ○
    use-back-button@ 1.0.0

    A Vue 3 composable to track back navigation in SPAs using Vue Router

    2025-06-11
  • ○
    historify@ 1.0.4

    Browser istory management for single page applications

    2024-06-27
  • ○
    js-interpreter-esm@ 1.0.3

    Neil Fraser's official JS-Interpreter

    2024-03-25
  • ○
    js-interpreter-npm@ 1.0.10

    NPM package for Neil Fraser's JS-Interpreter

    2024-03-22
  • ○
    jsonreststores-mysql@ 2.0.33

    Mixin to implement MySql calls for jsonreststores

    2024-01-26
  • ○
    routify-lit@ 2.0.3

    The most powerful client-side routing in the west

    2024-01-21
  • ○
    jsonreststores@ 2.0.19

    A module to create full Json REST stores in minutes

    2023-12-30
  • ●
    routify@ 2.0.1

    The most powerful client-side routing in the west

    2023-07-27
  • ○
    docco-next@ 0.9.14

    Literate programming parser

    2022-12-08
  • ○
    ejs4b@ 3.1.63

    EJS available for browsers as ES6 module

    2022-08-26
  • ○
    simpleschema@ 2.0.7

    The simplest, most extendible schema class you will ever come across

    2022-04-05
  • ○
    spa-data-loader@ 1.0.8

    A data loader for SPA (Single Page Applications)

    2022-02-20
  • ○
    web-sites-common@ 1.0.2

    Common properties for JS-KIT related web sites

    2022-02-20
  • ○
    eslint-plugin-literate-comments@ 1.0.3

    Plugin to allow col-1 literate comments in a file

    2022-02-20
  • ○
    spa-fetch@ 1.0.3

    Global fetch for Single Page Applications

    2022-02-17
  • ○
    best-webdriver@ 1.2.3

    Best webdriver around using async/await, simplified down-to-earth API, easy to debug, 1:1 matching with the webdriver API. You will be testing in 20 minutes, not 20 hours

    2021-11-28
  • ○
    tpe-demo@ 1.0.1
    2021-09-07
  • ○
    es6-dev-server@ 0.0.10

    Serve ES6 modules ensuring node resolution via the node algorithm. Express middleware and full server

    2021-09-05
  • ○
    lit-kit@ 1.0.0

    Scaffolding for lit applications

    2021-07-19
  • ○
    scaffoldizer-example@ 0.0.1

    An example scaffold

    2020-08-18
  • ○
    jsonreststores2@ 1.1.48

    A module to create full Json REST stores in minutes

    2020-02-05
  • ●
    reducs@ 0.0.10

    A sane implementation of Redux

    2019-10-30
  • ○
    simpleschema2@ 1.1.20

    The simplest, most extendible schema class you will ever come across

    2019-10-12
  • ○
    allhttperrors@ 0.4.2

    A module to create flexible, powerful Error objects based on HTTP responses

    2018-04-13
  • ○
    simpledblayer-mongo@ 0.3.57

    MongoDB layer for simpledblayer

    2017-12-20
  • ○
    hotplate@ 0.3.120

    Hotplate SaaS development framework

    2017-12-05
  • ○
    simpledblayer@ 0.3.38

    Simple, generic, no fuss DB layer for NodeJS

    2017-10-06
  • ○
    naps@ 0.1.7

    A multi-purpose node app manager

    2017-09-14
  • ○
    ryver@ 0.1.19

    Static web site generator

    2017-03-31
  • ○
    simpledeclare@ 0.3.29

    A simple implementation of declare() to have Javascript (single and multiple) inheritance in a very elegant, close-to-metal way

    2016-11-03
  • ○
    simpledblayer-tingo@ 0.3.29

    TingoDB layer for simpledblayer

    2016-04-15
  • public-github-push
    AUTO-PUBLISHED/npm/2019-10-27

    reducs@1.0.1

    by mercmobily

    A sane implementation of Redux

    → 의심 전송지 없음, 원격 실행 형태 없음 — 2 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    87
    size
    970 B
    versions
    5
    AUTO-PUBLISHED/npm/2020-02-19

    routify@1.0.0

    by mercmobily

    The most powerful client-side routing in the west

    → sends tohttps://github.com/mobilyenterprises/routify.git
    public-github-push

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    87
    patterns
    1
    size
    45.4 KB
    versions
    32