orbitron-cli — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend
The npm package orbitron-cli (publisher imjustbetterxd) poses as a CLI “inspired by codebuff.com's CLI” but routes the developer's authenticated AI traffic — API key, prompts and code — to an attacker-controlled backend (orbitron--pastelsjuice8t.replit.app), with TLS verification disabled in later builds. Part of the AI-CLI Relay Campaign.
orbitron-cli is published to npm by imjustbetterxd and presents as a CLI “inspired by codebuff.com's CLI”. It is one of five packages in the AI-CLI Relay Campaign.
How the relay works. On use, the CLI reads the developer's LLM / provider API key — from environment variables (e.g. EXA_API_KEY, NVIDIA_API_KEY, provider config) and its own settings — and routes the authenticated AI requests to an attacker-controlled default backend instead of the legitimate provider. Each request carries the user's Authorization: Bearer <apiKey> together with the chat prompt and code context, so whoever operates the backend receives the API key and everything the developer sends to their “AI”.
Default backend: orbitron--pastelsjuice8t.replit.app. It is a bun launcher: bin/orbitron imports dist/index.js, which uses dist/backend-client.js (holds the API key) and a bundled dist/orbitron binary. Notably, dist/update.js auto-updates from orbitron-tui's npm latest — the cluster is self-linked, so orbitron-cli pulls and runs orbitron-tui's payload.
TLS. Later builds set rejectUnauthorized: false / NODE_TLS_REJECT_UNAUTHORIZED for the relay connection, removing the last check on where the data actually goes.
Only one version is published (1.0.1, 2026-05-02) and it is malicious — the entire package is affected.
orbitron-cli published to npm by imjustbetterxd as part of the cluster.orbitron--pastelsjuice8t.replit.appdist/update.js auto-updates from registry.npmjs.org/orbitron-tui/latest and spawns the bundled dist/orbitron binaryAuthorization: Bearer), chat prompts and code context sent to the CLIrejectUnauthorized:false / NODE_TLS_REJECT_UNAUTHORIZED)imjustbetterxd; GitHub payload host github.com/Marcus-Mok-GHPart of the AI-CLI Relay Campaign (CLR-2026-3048). Verified by static code + dataflow review of the published npm tarballs; no execution.