LWA-2026-5156 confirmed malware
codyx-ai-windows-x64@1.14.42
Malicious code in codyx-ai-windows-x64 (npm)
T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or Information
Analysis
Package codyx-ai-windows-x64@1.14.42 ships a 154 MB Windows PE binary at package/bin/codyx.exe with no accompanying executable source code. The package declares os=win32 and cpu=x64 constraints. The binary cannot be audited by source inspection; it is an opaque payload delivered through the npm registry. No lifecycle hooks are present, so execution requires explicit invocation of the binary by a user or another package.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 11:43 PM
- analyzed
- Jun 13, 2026, 11:52 PM
- weekly installs
- 498
Related advisories
- codyx-ai-darwin-x64-baseline@1.14.42
- seed-to-private@1.0.1
- scraping-master@0.1.11
- scraping-master@0.1.10
- scraping-master@0.1.9
- scraping-master@0.1.8
- scraping-master@0.1.6
- scraping-master@0.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.