Cremit
/incidentsfield log
탐지캠페인유출지패턴LLM사고 사례방법론
↺rss↗cremit.io

incidents.cremit.io

실제 발생한 비인간 식별자(NHI) 크리덴셜 유출 사고를 정리한 인덱스. 운영: Cremit

둘러보기

  • 전체 사고
  • npm 공급망
  • CI/CD 침해
  • 방법론

구독

  • RSS 피드
  • @cremit_io
  • GitHub
// 상태
모니터 가동중
// 빌드
2026-07-17
// 출처
cremit · 서울, 대한민국
// 라이선스
CC BY 4.0

© 2026 Cremit. 출처 표시 시 자유롭게 재사용 가능.

home/campaigns/npm/yzl520

// publisher 캠페인 · npm

yzl520

npm의 yzl520 계정이 publish한 catch 패키지 전체와, registry가 현재 노출하는 author·maintainer 정보. 같은 이메일이나 이름이 여러 패키지에 걸쳐 등장하면, 한 명이 여러 throwaway 계정을 운영한다는 강한 증거입니다.

↗npmjs.com publisher↗pypi.org user
패키지
3
고유 이름 수
탐지 이벤트
3
버전 × 이름
blast
—
주간 다운로드 합계
활동 기간
2026-05-19 → 2026-05-19
최초 → 최근 탐지

// publisher OSINT

이 계정 자체에 대한 시그널. 활동 기간이 짧으면 throwaway 가능성이 큽니다. 이메일 도메인을 보면 단발 webmail인지 진짜 조직 메일인지 한눈에 갈리고, 같은 핸들이 여러 registry에 있으면 같은 운영자라고 볼 강한 근거가 됩니다. GitHub 링크가 잡히면 실명 식별까지 곧장 이어집니다.

npm 활동
  • registry 패키지 수: 49
  • 최초 publish: 2020-11-29
  • 최근 publish: 2026-07-13
  • 활동 기간: 2052일
다른 registry의 같은 핸들
  • npm /~yzl520: 존재함 ↗
  • pypi /user/yzl520: 존재함 ↗
  • github.com/yzl520: 존재함 ↗
이메일 도메인
  • gmail.com×3webmail
  • hotmail.com×3webmail
  • qq.com×3webmail

// exfil path

what is read → where it ships
steals
  • ○ home dir
→
sends to

(no destination string extracted — payload may be dynamic / obfuscated)

Targets resolved from static-analysis flags; destinations extracted from the captured code excerpt. Full list + structured fields available in the IOC panel below.

// 다른 publisher와 공유되는 이메일

이 캠페인의 이메일이 다른 publisher 계정의 catch 패키지에도 등장하는 경우. 한 운영자가 두 계정을 같이 굴리고 있다는 강한 증거입니다.

  • wzwahl36@qq.com
    also on 5 packages from 1 other publisher:
    • by
    • by
    • by
    • by
    • by

// 공유 author 식별자

같은 이메일·이름이 캠페인 안 여러 패키지에 등장하는 경우. publisher 계정 외에 별도로 잡히는 직접적인 attribution 증거입니다.

emails
  • loveyzl1123@gmail.com— @lint-md/parser, @lint-md/core, @lint-md/cli
  • luojiyin@hotmail.com— @lint-md/parser, @lint-md/core, @lint-md/cli
  • wzwahl36@qq.com— @lint-md/parser, @lint-md/core, @lint-md/cli
author names
  • hustcc— @lint-md/core, @lint-md/cli

// 패턴 풋프린트

캠페인 전반에서 어떤 정적 분석 플래그가 얼마나 자주 매칭됐는지. "이 캠페인이 결국 어떤 종류의 stealer인가"에 대한 요약 답.

  • ×1
  • ×1
  • ×1
  • ×1

// npm에 등록된 전체 활동

이 계정이 지금 registry에 올려둔 모든 패키지 (최신순). ● Cremit 파이프라인이 catch · ○ 아직 미검출.3/49 catch.

  • ●
    @ 2.2.2

    CLI tool to lint your markdown file for Chinese.

    2026-07-13
  • ●
    @ 2.1.5

    Core of lint-md which used to lint your markdown file for Chinese.

    2026-07-13
  • ●
    @ 0.1.2

    lint-md 的解析器,基于 remark 生态,将 Markdown 字符串转换成 AST

    2026-07-02
  • ○
    @attachments/babel-plugin-i18n@ 0.4.0

    > TODO: description

    2023-04-09

// 이 캠페인의 패키지

고유 이름 3개 · 최신순
  • ↳ author:yuzhanglong<loveyzl1123@gmail.com>maintainers: luojiyin <luojiyin@hotmail.com>, atool <wzwahl36@qq.com>, yzl520 <loveyzl1123@gmail.com>↗ registry
  • ↳ author:hustccmaintainers: luojiyin <luojiyin@hotmail.com>, atool <wzwahl36@qq.com>, yzl520 <loveyzl1123@gmail.com>↗ registry
  • ↳ author:hustccmaintainers: luojiyin <luojiyin@hotmail.com>, atool <wzwahl36@qq.com>, yzl520 <loveyzl1123@gmail.com>↗ registry
○
@attachments/assets@ 0.4.0

common resource tool packages, such as the CSS and project templates

2023-04-09
  • ○
    @attachments/proxy@ 0.4.0

    proxy server for front-end developers

    2023-04-09
  • ○
    @attachments/i18n@ 0.4.0

    > TODO: description

    2023-04-09
  • ○
    @attachments/hooks@ 0.4.0
    2023-04-09
  • ○
    @attachments/i18n-webpack-plugin@ 0.4.0

    > TODO: description

    2023-04-09
  • ○
    @attachments/eslint-config@ 0.4.0

    useful eslint config

    2023-04-09
  • ○
    @attachments/github-trending@ 0.4.0

    github trending API wrapper

    2023-04-09
  • ○
    @attachments/utils@ 0.4.0

    useful front-end development tool library

    2023-04-09
  • ○
    dependency-packager@ 0.0.0
    2023-04-01
  • ○
    @attachments/plop-plus@ 0.3.1

    > TODO: add description

    2022-10-29
  • ○
    @url-scheme/shared@ 0.0.0

    > TODO: add description

    2022-06-16
  • ○
    @attachments/eslint-plugin@ 0.2.2

    useful eslint-plugin

    2022-05-14
  • ○
    @url-scheme/core@ 0.0.1

    > TODO: add description

    2022-05-02
  • ○
    @attachments/monitor-sdk-browser@ 0.1.26

    TODO

    2021-12-15
  • ○
    @mf-lite/cli@ 0.1.9

    A scaffold for quickly creating base applications or micro-front-end applications from the command line

    2021-12-11
  • ○
    @mf-lite/core@ 0.1.9

    core library for mf-lite

    2021-12-11
  • ○
    find-my-code@ 0.0.0

    > TODO: add description

    2021-11-19
  • ○
    @attachments/monitor@ 0.1.19

    TODO

    2021-10-23
  • ○
    @mf-lite/module-federation-toolkits@ 0.0.1

    > TODO: description

    2021-10-18
  • ○
    @attachments/module-federation-toolkits@ 0.1.12

    > TODO: description

    2021-10-17
  • ○
    antd-onboarding@ 0.1.0

    <h1 align="center"> <b>antd-onboarding</b> </h1>

    2021-09-21
  • ○
    @attachments/i18n-babel-plugin@ 0.0.2

    > TODO: description

    2021-08-18
  • ○
    @attachments/serendipity-plugin-eslint@ 0.1.18

    ## 概述

    2021-06-15
  • ○
    @attachments/serendipity-plugin-babel@ 0.1.16

    babel plugin

    2021-06-14
  • ○
    @attachments/serendipity-scripts@ 0.1.16

    > TODO: description

    2021-06-14
  • ○
    @attachments/serendipity-plugin-typescript@ 0.1.16
    2021-06-14
  • ○
    @attachments/serendipity@ 0.1.16

    > cli manager for serendipity

    2021-06-14
  • ○
    @attachments/serendipity-plugin-react@ 0.1.16

    ## 概述

    2021-06-14
  • ○
    @attachments/serendipity-plugin-init@ 0.1.16

    ## 概述

    2021-06-14
  • ○
    @attachments/serendipity-core@ 0.1.16

    > TODO: description

    2021-06-14
  • ○
    @attachments/serendipity-webpack-plugin@ 0.1.16
    2021-06-14
  • ○
    @attachments/serendipity-public@ 0.1.16
    2021-06-14
  • ○
    limerence@ 0.0.1

    > TODO: description

    2021-04-27
  • ○
    @jest-electron/runner@ 0.0.3

    > TODO: description

    2021-03-31
  • ○
    @jest-electron/core@ 0.0.3

    > TODO: description

    2021-03-31
  • ○
    @lint-md/eslint-plugin@ 0.1.0

    :sunglasses: 基于 @lint-md,提供 eslint-plugin,让 lint-md 玩家得到愉悦的文档编写体验。

    2021-03-30
  • ○
    node-require-webpack-plugin@ 0.1.1

    为 node.js 环境下的 webpack 打包结果提供动态 require 支持。

    2021-03-30
  • ○
    redamancy@ 0.0.4
    2021-03-27
  • ○
    jest-electron-test@ 0.1.14

    Easiest way to run jest unit test cases in electron.

    2021-03-27
  • ○
    @attachments/serendipity-workflows@ 0.1.9
    2021-03-26
  • ○
    @lint-md/ast-plugin@ 1.0.1

    The simplest abstract syntax tree walker.

    2021-03-23
  • ○
    serendipity-core@ 0.1.7

    > TODO: description

    2021-03-14
  • ○
    eslint-plugin-lint-md@ 0.0.3

    依靠各个 IDE 对 eslint 不错的支持,让 lint-md 玩家也能得到愉悦的文档编写体验。

    2021-03-09
  • ○
    @attachments/serendipity-service-react@ 0.1.0
    2021-02-18
  • ○
    html-externals-webpack-plugin@ 0.0.2

    webpack plugin for externals

    2020-11-29
  • npm/@antv/l7-maps
    lzxue
    npm/@antv/l7-layers
    lzxue
    npm/@antv/l7
    lzxue
    npm/@antv/l7-core
    lzxue
    npm/@antv/l7-component
    lzxue
    install-path-npm-publish
    child-process-spawn
    public-github-push
    reads-homedir
    @lint-md/cli
    @lint-md/core
    @lint-md/parser
    AUTO-PUBLISHED/npm/2022-11-05/MAL-2026-4125

    @lint-md/parser@0.0.14

    by yzl520

    lint-md 的解析器,基于 remark 生态,将 Markdown 字符串转换成 AST

    → sends tohttps://github.com/lint-md

    → 의심 전송지 없음, 원격 실행 형태 없음 — 3 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    size
    1.9 MB
    versions
    15
    AUTO-PUBLISHED/npm/2023-07-12/MAL-2026-4124

    @lint-md/core@2.0.0

    by yzl520

    Core of lint-md which used to lint your markdown file for Chinese.

    install-path-npm-publishchild-process-spawn

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    2
    size
    208.1 KB
    versions
    23
    AUTO-PUBLISHED/npm/2023-07-12/MAL-2026-4123

    @lint-md/cli@2.0.0

    by yzl520

    CLI tool to lint your markdown file for Chinese.

    public-github-pushreads-homedir

    → 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    75
    patterns
    2
    size
    68.4 KB
    versions
    18