LWA-2026-5159 confirmed malware
codyx-ai-darwin-x64-baseline@1.14.42
Malicious code in codyx-ai-darwin-x64-baseline (npm)
T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or Information
Analysis
Package distributes a pre-compiled native binary (darwin x64, 107MB at bin/codyx) as a platform-specific dependency with no accompanying source code, lifecycle scripts, or install hooks. The binary cannot be audited by consumers. The publisher has previously uploaded multiple confirmed supply-chain attack packages under the same namespace and email handle, meaning the binary's provenance is compromised and it must be treated as potentially trojanized despite its surface appearance as an AI CLI tool referencing opencode[.]ai.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 11:45 PM
- analyzed
- Jun 13, 2026, 11:49 PM
- weekly installs
- 507
Related advisories
- seed-to-private@1.0.1
- scraping-master@0.1.11
- scraping-master@0.1.10
- scraping-master@0.1.9
- scraping-master@0.1.8
- scraping-master@0.1.6
- scraping-master@0.1.4
- rollup-runtime-polyfill-core@0.13.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.