Cremit
/incidentsfield log
탐지캠페인유출지패턴LLM사고 사례방법론
↺rss↗cremit.io

incidents.cremit.io

실제 발생한 비인간 식별자(NHI) 크리덴셜 유출 사고를 정리한 인덱스. 운영: Cremit

둘러보기

  • 전체 사고
  • npm 공급망
  • CI/CD 침해
  • 방법론

구독

  • RSS 피드
  • @cremit_io
  • GitHub
// 상태
모니터 가동중
// 빌드
2026-07-17
// 출처
cremit · 서울, 대한민국
// 라이선스
CC BY 4.0

© 2026 Cremit. 출처 표시 시 자유롭게 재사용 가능.

home/campaigns/npm/pomelo-nwu

// publisher 캠페인 · npm

pomelo-nwu

npm의 pomelo-nwu 계정이 publish한 catch 패키지 전체와, registry가 현재 노출하는 author·maintainer 정보. 같은 이메일이나 이름이 여러 패키지에 걸쳐 등장하면, 한 명이 여러 throwaway 계정을 운영한다는 강한 증거입니다.

↗npmjs.com publisher↗pypi.org user
패키지
3
고유 이름 수
탐지 이벤트
3
버전 × 이름
blast
50/wk
주간 다운로드 합계
활동 기간
2026-05-19 → 2026-05-19
최초 → 최근 탐지

// publisher OSINT

이 계정 자체에 대한 시그널. 활동 기간이 짧으면 throwaway 가능성이 큽니다. 이메일 도메인을 보면 단발 webmail인지 진짜 조직 메일인지 한눈에 갈리고, 같은 핸들이 여러 registry에 있으면 같은 운영자라고 볼 강한 근거가 됩니다. GitHub 링크가 잡히면 실명 식별까지 곧장 이어집니다.

npm 활동
  • registry 패키지 수: 64
  • 최초 publish: 2017-05-16
  • 최근 publish: 2026-07-16
  • 활동 기간: 3348일
다른 registry의 같은 핸들
  • npm /~pomelo-nwu: 존재함 ↗
  • pypi /user/pomelo-nwu: 존재함 ↗
  • github.com/pomelo-nwu: 존재함 ↗
이메일 도메인
  • qq.com×21webmail
  • gmail.com×15webmail
  • 163.com×6webmail
  • outlook.com×3webmail
  • antgroup.com×3

// 다른 publisher와 공유되는 이메일

이 캠페인의 이메일이 다른 publisher 계정의 catch 패키지에도 등장하는 경우. 한 운영자가 두 계정을 같이 굴리고 있다는 강한 증거입니다.

  • yunji.me@outlook.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by
  • 943720372@qq.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by
  • jinke.li666@gmail.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by
  • 120635640@qq.com
    also on 5 packages from 1 other publisher:

// 공유 author 식별자

같은 이메일·이름이 캠페인 안 여러 패키지에 등장하는 경우. publisher 계정 외에 별도로 잡히는 직접적인 attribution 증거입니다.

emails
  • yunji.me@outlook.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • 943720372@qq.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • jinke.li666@gmail.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • 120635640@qq.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • army8735@qq.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • dengfuping_private@163.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • afc163@gmail.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • chenluuli@gmail.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • 1175863618@qq.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • 1491812683@qq.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • zhuyuxin0627@gmail.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons

// 패턴 풋프린트

캠페인 전반에서 어떤 정적 분석 플래그가 얼마나 자주 매칭됐는지. "이 캠페인이 결국 어떤 종류의 stealer인가"에 대한 요약 답.

  • ×2
  • ×2

// npm에 등록된 전체 활동

이 계정이 지금 registry에 올려둔 모든 패키지 (최신순). ● Cremit 파이프라인이 catch · ○ 아직 미검출.0/64 catch.

  • ○
    @qwen-code/channel-base@ 0.19.11

    Base channel infrastructure for Qwen Code

    2026-07-16
  • ○
    @qwen-code/qwen-code@ 0.19.11

    Qwen Code - AI-powered coding assistant

    2026-07-16
  • ○
    @qwen-code/audio-capture@ 0.19.11

    Native microphone capture backend for Qwen Code voice input

    2026-07-16
  • ○
    @qwen-code/sdk

// 이 캠페인의 패키지

고유 이름 3개 · 최신순
  • ↳ author:maintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • ↳ author:maintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • ↳ author:maintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • npm/@antv/l7-mapsby lzxue
  • npm/@antv/l7by lzxue
  • npm/@antv/l7-layersby lzxue
  • npm/@antv/l7-coreby lzxue
  • npm/@antv/l7-componentby lzxue
  • army8735@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • dengfuping_private@163.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • afc163@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • chenluuli@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • 1175863618@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • 1491812683@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • zhuyuxin0627@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • ojh496845051@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • wzwahl36@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • 610999886@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • alex_zjt@163.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • duxinyue.dxy@antgroup.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • ojh496845051@gmail.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • wzwahl36@qq.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • 610999886@qq.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • alex_zjt@163.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • duxinyue.dxy@antgroup.com— @antv/gi-mock-data, @antv/gi-public-data, @antv/graphin-icons
  • @ 0.1.8

    TypeScript SDK for programmatic access to qwen-code CLI

    2026-07-14
  • ○
    @qwen-code/mobile-mcp@ 0.1.3

    Mobile MCP with opt-in relative coordinate support

    2026-07-10
  • ○
    @qwen-code/open-computer-use@ 0.2.3

    Cross-platform Computer Use MCP server launcher. After install, configure open-computer-use mcp.

    2026-06-03
  • ○
    @qwen-code/channel-plugin-example@ 0.14.0-preview.1

    A reference channel plugin for Qwen Code. It connects to a WebSocket server and routes messages through the full channel pipeline (access control, session routing, agent bridge).

    2026-03-27
  • ○
    @qwen-code/translator@ 0.0.3

    A universal documentation translator for any GitHub project. Instantly translate docs with AI and automatically build a Nextra-based documentation site.

    2026-02-03
  • ○
    @qwen-code/webui@ 0.1.0-beta.4

    Shared UI components for Qwen Code packages

    2026-01-28
  • ○
    @qwen-code/qwen-code-core@ 0.0.14

    Qwen Code Core

    2025-09-29
  • ○
    @graphscope/neug-query@ 0.2.2

    Neug Query - A standalone query interface for GraphScope

    2025-08-27
  • ○
    @graphscope/studio-query@ 0.1.20

    A data querying module in GraphStudio, supporting Cypher and Gremlin statements

    2025-08-26
  • ○
    @graphscope/studio-explore@ 0.1.18
    2025-08-26
  • ○
    @graphscope/graphy-website@ 0.1.14

    ## Quick Start

    2025-08-26
  • ○
    @graphscope/studio-site@ 0.1.20

    ## Development

    2025-08-26
  • ○
    @dashscope-js/claude-code-config@ 0.1.8

    Default configuration for claude-code-router with DashScope support

    2025-08-07
  • ○
    claude-fetch-setup@ 0.1.2

    A tool to automatically setup fetch MCP and configure global CLAUDE.md for Claude Code in enterprise environments

    2025-08-05
  • ○
    @graphscope/claude-code-router-helper@ 0.1.3

    Default configuration for claude-code-router with DashScope support

    2025-07-19
  • ○
    @graphscope/studio-flow-editor@ 0.1.13

    一个基于 ReactFlow 的流程图编辑器组件,提供图形化编辑、节点管理、边连接等功能。

    2025-04-24
  • ○
    @graphscope/duckdb-admin@ 1.0.0

    A web-based tool for querying CSV files using DuckDB

    2025-04-08
  • ○
    @graphscope/use-zustand@ 0.1.11

    A state management for React

    2025-04-01
  • ○
    @graphscope/studio-importor@ 0.1.19

    A data modeling and import module in GraphStudio

    2025-04-01
  • ○
    @graphscope/studio-components@ 0.1.19

    A components for graphscope studio

    2025-04-01
  • ○
    @graphscope/studio-graph@ 0.1.19

    A React toolkit for graph analysis based on g6

    2025-04-01
  • ○
    @graphscope/studio-draw-pattern@ 0.0.15

    Experiment draw pattern code for GrapeScope

    2025-04-01
  • ○
    @graphscope/studio-graph-editor@ 0.1.13

    - warning: 目前还没有对 `Table-Node` 进行 `API` 支持。

    2025-04-01
  • ○
    @graphscope/studio-driver@ 0.1.17

    A library provides a unified interface for interacting with graph databases

    2025-04-01
  • ○
    @graphscope/studio-server@ 1.0.16

    OpenAPI client for GraphScope Studio

    2025-04-01
  • ○
    mcp-portal@ 1.0.0
    2025-03-10
  • ○
    @graphscope/graph-apps@ 0.1.5

    Graph Apps

    2024-10-09
  • ○
    @graphscope/studtio-graph-editor@ 0.1.4
    2024-09-23
  • ○
    llm-workflow-graph@ 0.1.1
    2024-09-03
  • ○
    @tugraph/gi-assets-tugraph-db@ 0.6.43

    G6VP Assets for TuGraph-DB

    2024-04-19
  • ○
    @graphscope/_test_gremlin_@ 0.1.2

    JavaScript Gremlin Language Variant

    2024-03-15
  • ○
    @tugraph/preset-openpiece@ 0.0.41
    2023-08-07
  • ○
    @tugraph/plugin-acl@ 0.0.15
    2023-08-07
  • ○
    @tugraph/plugin-multi-app-manager@ 0.0.4

    多应用管理插件,Openpiece 默认会内置该插件。

    2023-08-07
  • ○
    @tugraph/plugin-ui-schema-storage@ 0.0.5
    2023-08-07
  • ○
    @tugraph/plugin-users@ 0.0.14
    2023-08-07
  • ○
    @tugraph/plugin-ui-routes-storage@ 0.0.14
    2023-08-07
  • ○
    @tugraph/plugin-system-settings@ 0.0.15
    2023-08-07
  • ○
    @tugraph/plugin-file-manager@ 0.0.17
    2023-08-07
  • ○
    @tugraph/plugin-collection-manager@ 0.0.14
    2023-08-07
  • ○
    @tugraph/plugin-client@ 0.0.15
    2023-08-07
  • ○
    @tugraph/plugin-git-workflow@ 0.0.3
    2023-08-07
  • ○
    @tugraph/openpiece-server@ 0.0.13
    2023-08-07
  • ○
    @tugraph/actions@ 0.0.4
    2023-08-07
  • ○
    @tugraph/database@ 0.0.4
    2023-08-07
  • ○
    @tugraph/openpiece-client@ 0.0.21

    fork by Nocobase.

    2023-07-14
  • ○
    @tugraph/openpiece-client-app@ 0.0.11
    2023-06-27
  • ○
    @tugraph/openpiece-server-app@ 0.0.18
    2023-06-21
  • ○
    @tugraph/openpiece-cli@ 0.0.7
    2023-06-21
  • ○
    @tugraph/openpiece-sdk@ 0.0.1
    2023-06-21
  • ○
    @tugraph/create-openpiece-app@ 0.0.7
    2023-05-09
  • ○
    @tugraph/plugin-sample-hello@ 0.0.3

    ## Register

    2023-03-23
  • ○
    @tugraph/openpiece-devtools@ 0.0.5
    2023-02-28
  • ○
    dumi-theme-graphin@ 0.1.4

    The official graphin theme of dumi

    2021-08-24
  • ○
    @graphscope/graphscope-jupyter@ 0.4.1

    A GraphScope Jupyter Extension, including Graphin Widget, etc.

    2021-05-16
  • ○
    pay-cli@ 1.4.5

    CLI for DPAY.JS powered by payTeam

    2019-05-14
  • ○
    payui@ 0.6.26

    React UI library based on Pay.css

    2018-12-11
  • ○
    google-search-for-react@ 0.1.0

    A simple search components it's UI just like google search

    2018-11-08
  • ○
    watermark-for-react@ 0.1.0

    watermark components for React

    2018-11-07
  • ○
    @payteam/payui@ 0.1.5

    payui for react

    2018-02-01
  • ○
    react-codemirror-pay@ 1.0.0

    react-codemirror-pay based on react and codemirror

    2017-05-16
  • npm/@antv/l7-maps
    lzxue
    npm/@antv/l7
    lzxue
    npm/@antv/l7-layers
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-component
    lzxue
    npm/@antv/l7-maps
    lzxue
    npm/@antv/l7
    lzxue
    npm/@antv/l7-layers
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-component
    lzxue
    npm/@antv/l7-maps
    lzxue
    npm/@antv/l7
    lzxue
    npm/@antv/l7-layers
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-component
    lzxue
    public-github-push
    archive-then-upload
    AUTO-PUBLISHED/npm/2021-01-20/MAL-2026-4025

    @antv/graphin-icons@1.0.0

    by pomelo-nwu

    graphin icon fonts

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    size
    75.0 KB
    versions
    1
    AUTO-PUBLISHED/npm/2023-07-21/MAL-2026-4014

    @antv/gi-public-data@1.0.1

    by pomelo-nwu

    G6VP public data

    → sends tohttps://github.com/antvis/G6VP.git
    public-github-pusharchive-then-upload

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    2
    size
    1.2 MB
    versions
    2
    AUTO-PUBLISHED/npm/2023-03-11/MAL-2026-4013

    @antv/gi-mock-data@1.0.5

    by pomelo-nwu

    G6VP MOCK DATA

    → sends tohttps://github.com/antvis/G6VP.git
    public-github-pusharchive-then-upload

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    50
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    2
    size
    282.5 KB
    versions
    6