LWA-2026-5158 confirmed malware

codyx-ai-windows-x64-baseline@1.14.42

Malicious code in codyx-ai-windows-x64-baseline (npm)

T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or Information

Analysis

Package ships a 161MB Windows PE binary (codyx.exe in bin/) with no accompanying source code, scripts, or documentation. The binary executes when the package is invoked on Windows x64 systems and cannot be inspected at the JS level. The package was published by an email address with a known history of shipping malicious packages, and the binary-only distribution model is used to evade static analysis of the payload.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 11:44 PM
analyzed
Jun 13, 2026, 11:52 PM
weekly installs
496

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.