The Gemini CLI impersonation campaign was first publicly identified by independent threat researcher @g0njxa[1], whose initial discovery enabled analysis and infrastructure pivoting documented in this report. The infection chain begins with a Google search by a developer looking for the official Gemini CLI[2]or Claude Code[3]installation page. Threat actors use SEO poisoning to surface a fake…