codyx-ai-linux-x64-baseline@1.14.42
Malicious code in codyx-ai-linux-x64-baseline (npm)
Analysis
Package ships a 148MB precompiled binary at package/bin/codyx as its sole payload. No JavaScript source code, no lifecycle hooks, and no executable entry points are included — the package cannot execute on its own during install. The binary is a Bun-compiled CLI application containing embedded API key configuration logic for AI providers (OpenAI, Anthropic, Cloudflare, Vercel, AWS) and references to opencode[.]ai as a service endpoint. The binary cannot be source-audited and may contain hidden runtime behaviour that is not visible from static string analysis. No network IOCs or exfiltration endpoints were identifiable from static analysis alone.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 11:41 PM
- analyzed
- Jun 13, 2026, 11:43 PM
- weekly installs
- 530
Related advisories
- simple-auth-basic@2.0.2
- signature-transaction@1.1.0
- sftc-advance-components@0.9.9
- session-exp@1.3.20
- sentrykit@30.0.0
- seed-to-private@1.0.1
- search-reservation@55.0.0
- rollup-runtime-polyfill-core@0.13.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.