mal-2026-16011

osv_npm
Description

The npm package `orbitron-tui` is malicious. It is one of five AI-coding-CLI impersonations published to npm by `imjustbetterxd` (a coordinated campaign). On use, the CLI reads the developer's LLM/provider API key - from environment variables (e.g. EXA_API_KEY, NVIDIA_API_KEY) and its own config - and routes the authenticated AI requests to an attacker-controlled default backend instead of the legitimate provider. Each request carries the user's `Authorization: Bearer <apiKey>` together with the chat prompt and code context, so the backend operator receives the API key and everything the developer sends to their assistant. Later builds set `rejectUnauthorized: false` / `NODE_TLS_REJECT_UNAUTHORIZED` for the relay connection. Payloads/updates are hosted on the GitHub account `Marcus-Mok-GH`. All 84 published versions (0.1.2 through 1.0.29) are affected - the relay is present from the very first version (0.1.2), so the entire package is malicious. The relay backend rotated from `orbitron--pastelsjuice8t.replit.app` (0.1.x-0.4.x) to `fireworks-endpoint--57crestcrepe.replit.app` (1.0.x, the same host used by codebuff-cli and agent-free). The `bin` entry launches a bundled binary that performs the relay.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/orbitron-tui/MAL-2026-16011.json"
      },
      "package": {
        "ecosystem": "npm",
        "name": "orbitron-tui",
        "purl": "pkg:npm/orbitron-tui"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "SEMVER"
        }
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "https://research.codelake.dev/advisories/clr-2026-3049-orbitron-tui"
      ],
      "name": "codelake Research",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "iocs": {
      "domains": [
        "orbitron--pastelsjuice8t.replit.app",
        "fireworks-endpoint--57crestcrepe.replit.app"
      ]
    }
  },
  "details": "The npm package `orbitron-tui` is malicious. It is one of five AI-coding-CLI impersonations published to npm by `imjustbetterxd` (a coordinated campaign). On use, the CLI reads the developer's LLM/provider API key - from environment variables (e.g. EXA_API_KEY, NVIDIA_API_KEY) and its own config - and routes the authenticated AI requests to an attacker-controlled default backend instead of the legitimate provider. Each request carries the user's `Authorization: Bearer <apiKey>` together with the chat prompt and code context, so the backend operator receives the API key and everything the developer sends to their assistant. Later builds set `rejectUnauthorized: false` / `NODE_TLS_REJECT_UNAUTHORIZED` for the relay connection. Payloads/updates are hosted on the GitHub account `Marcus-Mok-GH`.\n\nAll 84 published versions (0.1.2 through 1.0.29) are affected - the relay is present from the very first version (0.1.2), so the entire package is malicious. The relay backend rotated from `orbitron--pastelsjuice8t.replit.app` (0.1.x-0.4.x) to `fireworks-endpoint--57crestcrepe.replit.app` (1.0.x, the same host used by codebuff-cli and agent-free). The `bin` entry launches a bundled binary that performs the relay.",
  "id": "MAL-2026-16011",
  "modified": "2026-09-11T04:00:06.567490512Z",
  "published": "2026-09-04T00:00:00Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3049-orbitron-tui"
    },
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3048-ai-cli-relay-campaign"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "Malicious code in orbitron-tui (npm)"
}
View JSON API Download JSON