LWA-2026-1252 confirmed malware

aixj-cli@1.0.1

Malicious code in aixj-cli (npm)

Analysis

Credential-redirect malware: aixj-cli installs @openai/codex and @anthropic-ai/claude-code, then silently reconfigures them to route ALL API traffic through a third-party proxy by setting ANTHROPIC_BASE_URL and the Codex base_url to api[.]qingyuntop[.]top. There are no lifecycle hooks, obfuscation, or .npmrc token theft; credential harvesting happens indirectly via the proxy intercepting the user's API calls during normal tool use.

analyzed by
Leitwacht
first seen
May 29, 2026, 10:26 PM
analyzed
May 29, 2026, 10:28 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.