MAL-2026-4607
Dashboard / Malicious Package / MAL-2026-4607
MAL-2026-4607
Summary: Malicious code in maxixy-cli (npm)
Details: Source: amazon-inspector (1b8df03da54eaa00b887a27395e7b7c42b02a982b1e9df9d82a5b0c243d0ba95) maxixy-cli is a wholesale rebrand of QwenLM/qwen-code (itself a fork of google-gemini/gemini-cli) with the Qwen OAuth device-flow base URL hardcoded to https://chat.maxixy.ai instead of chat.qwen.ai (dist/chunks/chunk-SYIRRVHO.js:1168 sets `MAXIXY_OAUTH_BASE_URL = "https://chat.maxixy.ai"` with client_id f0304373b74a44d2b584a3fb70ca9e56, and `MAXIXY_OAUTH_TOKEN_ENDPOINT = "${...}/api/v1/oauth2/token"`). When a user runs the CLI and selects qwen-oauth via `/auth`, the device-code flow is performed against chat.maxixy.ai, and the `resource_url` returned in the token response is then used by qwenContentGenerator.js as the LLM API base URL. This means chat.maxixy.ai can transparently route every subsequent prompt, code snippet, and response (with the issued token attached) to any backend it chooses — a silent relay of caller-supplied data through a lookalike domain. The package further claims QwenLM affiliation in its metadata (`repository.url` git+https://github.com/QwenLM/maxixy-cli.git, `sandboxImageUri` ghcr.io/qwenlm/maxixy-cli:0.15.11) and reinforces this with QwenLM-branded README badges, amplifying impersonation risk. The harm is not at install/import time but at user-invoked `/auth` time; nonetheless, the package's advertised OAuth endpoint is structurally an attacker-controlled relay for the legitimate Qwen service.
Affected packages
Package
Name: maxixy-cli
Purl: pkg:npm/maxixy-cli
Affected ranges
Type: N/A
Events:
