@quantum-ai/gemini-cli@0.45.1
Malicious code in @quantum-ai/gemini-cli (npm)
Analysis
Package is a combosquat of @google/gemini-cli — it uses the same basename "gemini-cli" under the @quantum-ai scope instead of @google. The package.json contains dependency overrides that substitute the `ink` terminal-rendering library (a core dependency of the CLI) with `@jrichman/ink@6.6.9`, and substitutes `prebuild-install` with `nop@1.0.0` and `node-domexception` with `empty@^0.10.1` — a dependency-substitution attack that hijacks the CLI's runtime execution flow. The repository URL misleadingly points to the official Google Gemini CLI repository. There are no install-time lifecycle hooks; the substituted dependencies would activate when the binary is executed.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 10:30 PM
- analyzed
- Jun 25, 2026, 10:32 PM
Related advisories
- @diezyyasha/libsignal-node@2.2.8
- native-hello-plugin@1.2.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- free-anthropic-claude@5.3.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2
- @salem_jalal/osc-components@1981.17.7
- dttsdee@1.0.0
- dddooo@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.