codyx-ai-linux-x64-baseline-musl@1.14.42
Malicious code in codyx-ai-linux-x64-baseline-musl (npm)
Analysis
Package ships a 137MB standalone compiled binary (package/bin/codyx) containing an embedded JavaScript CLI application with agent management, upgrade, and uninstall commands referencing opencode[.]ai as a provider. The binary is compiled with the Bun JavaScript runtime. The package has no lifecycle hooks, no npm bin entries, and no executable code files — the binary is inert on installation with no auto-execution mechanism. The package name follows a platform-specific distribution pattern (linux-x64-musl) consistent with infrastructure reserved for a multi-package supply-chain attack: the package serves as a platform-specific dependency that would be consumed by a main package, with no malicious runtime behaviour observable from the static binary content alone.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 11:43 PM
- analyzed
- Jun 13, 2026, 11:46 PM
- weekly installs
- 530
Related advisories
- codyx-ai-linux-x64@1.14.42
- codyx-ai-linux-x64-baseline@1.14.42
- simple-auth-basic@2.0.2
- signature-transaction@1.1.0
- sftc-advance-components@0.9.9
- session-exp@1.3.20
- sentrykit@30.0.0
- seed-to-private@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.