LWA-2026-5156 confirmed malware

codyx-ai-windows-x64@1.14.42

Malicious code in codyx-ai-windows-x64 (npm)

T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or Information

Analysis

Package codyx-ai-windows-x64@1.14.42 ships a 154 MB Windows PE binary at package/bin/codyx.exe with no accompanying executable source code. The package declares os=win32 and cpu=x64 constraints. The binary cannot be audited by source inspection; it is an opaque payload delivered through the npm registry. No lifecycle hooks are present, so execution requires explicit invocation of the binary by a user or another package.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 11:43 PM
analyzed
Jun 13, 2026, 11:52 PM
weekly installs
498

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.