LWA-2026-5980 confirmed malware

@quantum-ai/gemini-cli@0.45.1

Malicious code in @quantum-ai/gemini-cli (npm)

T1195.002 · Compromise Software Supply ChainT1574.002 · DLL Side-LoadingT1059.007 · JavaScript

Analysis

Package is a combosquat of @google/gemini-cli — it uses the same basename "gemini-cli" under the @quantum-ai scope instead of @google. The package.json contains dependency overrides that substitute the `ink` terminal-rendering library (a core dependency of the CLI) with `@jrichman/ink@6.6.9`, and substitutes `prebuild-install` with `nop@1.0.0` and `node-domexception` with `empty@^0.10.1` — a dependency-substitution attack that hijacks the CLI's runtime execution flow. The repository URL misleadingly points to the official Google Gemini CLI repository. There are no install-time lifecycle hooks; the substituted dependencies would activate when the binary is executed.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 10:30 PM
analyzed
Jun 25, 2026, 10:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.