Cremit
/incidentsfield log
탐지캠페인유출지패턴LLM사고 사례방법론
↺rss↗cremit.io

incidents.cremit.io

실제 발생한 비인간 식별자(NHI) 크리덴셜 유출 사고를 정리한 인덱스. 운영: Cremit

둘러보기

  • 전체 사고
  • npm 공급망
  • CI/CD 침해
  • 방법론

구독

  • RSS 피드
  • @cremit_io
  • GitHub
// 상태
모니터 가동중
// 빌드
2026-06-15
// 출처
cremit · 서울, 대한민국
// 라이선스
CC BY 4.0

© 2026 Cremit. 출처 표시 시 자유롭게 재사용 가능.

home/campaigns/npm/xuying1027

// publisher 캠페인 · npm

xuying1027

npm의 xuying1027 계정이 publish한 catch 패키지 전체와, registry가 현재 노출하는 author·maintainer 정보. 같은 이메일이나 이름이 여러 패키지에 걸쳐 등장하면, 한 명이 여러 throwaway 계정을 운영한다는 강한 증거입니다.

↗npmjs.com publisher↗pypi.org user
패키지
6
고유 이름 수
탐지 이벤트
6
버전 × 이름
blast
76/wk
주간 다운로드 합계
활동 기간
2026-05-19 → 2026-05-19
최초 → 최근 탐지

// publisher OSINT

이 계정 자체에 대한 시그널. 활동 기간이 짧으면 throwaway 가능성이 큽니다. 이메일 도메인을 보면 단발 webmail인지 진짜 조직 메일인지 한눈에 갈리고, 같은 핸들이 여러 registry에 있으면 같은 운영자라고 볼 강한 근거가 됩니다. GitHub 링크가 잡히면 실명 식별까지 곧장 이어집니다.

npm 활동

이 에코시스템에서는 사용할 수 없습니다 (registry search 미지원).

다른 registry의 같은 핸들
  • npm /~xuying1027: 없음
  • pypi /user/xuying1027: 존재함 ↗
  • github.com/xuying1027: 없음
이메일 도메인
  • qq.com×42webmail
  • gmail.com×30webmail
  • 163.com×12webmail
  • outlook.com×6webmail
  • antgroup.com×6

// 다른 publisher와 공유되는 이메일

이 캠페인의 이메일이 다른 publisher 계정의 catch 패키지에도 등장하는 경우. 한 운영자가 두 계정을 같이 굴리고 있다는 강한 증거입니다.

  • yunji.me@outlook.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by
  • 943720372@qq.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by
  • jinke.li666@gmail.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by
  • 120635640@qq.com
    also on 5 packages from 1 other publisher:

// 공유 author 식별자

같은 이메일·이름이 캠페인 안 여러 패키지에 등장하는 경우. publisher 계정 외에 별도로 잡히는 직접적인 attribution 증거입니다.

emails
  • yunji.me@outlook.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • 943720372@qq.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • jinke.li666@gmail.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • 120635640@qq.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • army8735@qq.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • dengfuping_private@163.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • afc163@gmail.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • chenluuli@gmail.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • 1175863618@qq.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • 1491812683@qq.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine

// 패턴 풋프린트

캠페인 전반에서 어떤 정적 분석 플래그가 얼마나 자주 매칭됐는지. "이 캠페인이 결국 어떤 종류의 stealer인가"에 대한 요약 답.

  • ×2
  • ×1

// 이 캠페인의 패키지

고유 이름 6개 · 최신순
  • ↳ author:https://github.com/orgs/antvis/peoplemaintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • ↳ author:https://github.com/orgs/antvis/peoplemaintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • ↳ author:https://github.com/orgs/antvis/peoplemaintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • npm/@antv/l7-layersby lzxue
  • npm/@antv/l7by lzxue
  • npm/@antv/l7-mapsby lzxue
  • npm/@antv/l7-coreby lzxue
  • npm/@antv/l7-componentby lzxue
  • army8735@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • dengfuping_private@163.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • afc163@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • chenluuli@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • 1175863618@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • 1491812683@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • zhuyuxin0627@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • ojh496845051@gmail.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • wzwahl36@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • 610999886@qq.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • alex_zjt@163.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • duxinyue.dxy@antgroup.com
    also on 5 packages from 1 other publisher:
    • npm/@antv/l7-layersby lzxue
    • npm/@antv/l7by lzxue
    • npm/@antv/l7-mapsby lzxue
    • npm/@antv/l7-coreby lzxue
    • npm/@antv/l7-componentby lzxue
  • zhuyuxin0627@gmail.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • ojh496845051@gmail.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • wzwahl36@qq.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • 610999886@qq.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • alex_zjt@163.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • duxinyue.dxy@antgroup.com— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • author names
    • https://github.com/orgs/antvis/people— @antv/f-wx, @antv/f-vue, @antv/f-react, @antv/f-my, @antv/f-lottie, @antv/f-engine
  • AUTO-PUBLISHED/npm/2026-01-21/MAL-2026-3884

    @antv/f-my@1.10.0

    by xuying1027

    FEngine for alipay mini-program

    child-process-spawn

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    1
    size
    ↳ author:https://github.com/orgs/antvis/peoplemaintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • AUTO-PUBLISHED/npm/2026-01-21/MAL-2026-3883

    @antv/f-lottie@1.10.0

    by xuying1027

    FEngine for Lottie

    → sends tohttps://f2.antv.vision

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    size
    14.3 KB
    ↳ author:https://github.com/orgs/antvis/peoplemaintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • AUTO-PUBLISHED/npm/2026-01-21/MAL-2026-3882

    @antv/f-engine@1.10.0

    by xuying1027

    FEngine 是 AntV F 系列可视化引擎的底层渲染引擎,为移动端提供了一套完整的渲染、事件、动画能力,能方便的构建可视化 UI

    → sends tohttps://github.com/antvis/FEngine
    reads-env-vars

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    ↳ author:https://github.com/orgs/antvis/peoplemaintainers: lvisei <yunji.me@outlook.com>, iaaron <943720372@qq.com>, jinke.li <jinke.li666@gmail.com>, lzxue <120635640@qq.com>, army8735 <army8735@qq.com>, dengfuping <dengfuping_private@163.com>, afc163 <afc163@gmail.com>, chenluli <chenluuli@gmail.com>, kn9117 <1175863618@qq.com>, bbsqq <1491812683@qq.com>, banxuan <zhuyuxin0627@gmail.com>, yanxiong <ojh496845051@gmail.com>, atool <wzwahl36@qq.com>, pearl_wang <610999886@qq.com>, alex_zjt <alex_zjt@163.com>, duxinyue023 <duxinyue.dxy@antgroup.com>↗ registry
  • npm/@antv/l7-layers
    lzxue
    npm/@antv/l7
    lzxue
    npm/@antv/l7-maps
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-component
    lzxue
    npm/@antv/l7-layers
    lzxue
    npm/@antv/l7
    lzxue
    npm/@antv/l7-maps
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-component
    lzxue
    npm/@antv/l7-layers
    lzxue
    npm/@antv/l7
    lzxue
    npm/@antv/l7-maps
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-component
    lzxue
    child-process-spawn
    reads-env-vars
    AUTO-PUBLISHED/npm/2026-01-21/MAL-2026-3888

    @antv/f-wx@1.10.0

    by xuying1027

    FEngine for weixin mini-program

    child-process-spawn

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    1
    size
    17.8 KB
    versions
    78
    AUTO-PUBLISHED/npm/2026-01-21/MAL-2026-3887

    @antv/f-vue@1.10.0

    by xuying1027

    FEngine for Vue.js

    → sends tohttps://f2.antv.vision/zh/docs/tutorial/vue

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    76
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    size
    17.2 KB
    versions
    77
    AUTO-PUBLISHED/npm/2026-01-21/MAL-2026-3885

    @antv/f-react@1.10.0

    by xuying1027

    FEngine for React

    → sends tohttps://f2.antv.vision/zh/docs/tutorial/react

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    size
    35.7 KB
    versions
    82
    102.7 KB
    versions
    93
    versions
    80
    patterns
    1
    size
    2.0 MB
    versions
    83