LWA-2026-5160 confirmed malware
codyx-ai-windows-arm64@1.14.42
Malicious code in codyx-ai-windows-arm64 (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Ships a 158MB Windows ARM64 binary (package/bin/codyx.exe) under a package name that resembles the Cody AI coding-assistant ecosystem. The package contains no JavaScript source, no lifecycle hooks — only the compiled PE binary. Users on Windows ARM64 who install this package will have the binary available on their system. The binary's behaviour cannot be determined from static inspection alone and requires independent reverse-engineering on a Windows ARM64 environment.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 11:42 PM
- analyzed
- Jun 13, 2026, 11:52 PM
- weekly installs
- 402
Related advisories
- codyx-ai-darwin-x64-baseline@1.14.42
- codyx-ai-linux-x64-baseline-musl@1.14.42
- codyx-ai-linux-x64@1.14.42
- codyx-ai-linux-x64-baseline@1.14.42
- simple-auth-basic@2.0.2
- signature-transaction@1.1.0
- sftc-advance-components@0.9.9
- session-exp@1.3.20
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.