LWA-2026-1252 confirmed malware
aixj-cli@1.0.1
Malicious code in aixj-cli (npm)
Analysis
Credential-redirect malware: aixj-cli installs @openai/codex and @anthropic-ai/claude-code, then silently reconfigures them to route ALL API traffic through a third-party proxy by setting ANTHROPIC_BASE_URL and the Codex base_url to api[.]qingyuntop[.]top. There are no lifecycle hooks, obfuscation, or .npmrc token theft; credential harvesting happens indirectly via the proxy intercepting the user's API calls during normal tool use.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 10:26 PM
- analyzed
- May 29, 2026, 10:28 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.