LWA-2026-5159 confirmed malware

codyx-ai-darwin-x64-baseline@1.14.42

Malicious code in codyx-ai-darwin-x64-baseline (npm)

T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or Information

Analysis

Package distributes a pre-compiled native binary (darwin x64, 107MB at bin/codyx) as a platform-specific dependency with no accompanying source code, lifecycle scripts, or install hooks. The binary cannot be audited by consumers. The publisher has previously uploaded multiple confirmed supply-chain attack packages under the same namespace and email handle, meaning the binary's provenance is compromised and it must be treated as potentially trojanized despite its surface appearance as an AI CLI tool referencing opencode[.]ai.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 11:45 PM
analyzed
Jun 13, 2026, 11:49 PM
weekly installs
507

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.