LWA-2026-5161 confirmed malware

codyx-ai-linux-x64-baseline-musl@1.14.42

Malicious code in codyx-ai-linux-x64-baseline-musl (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package ships a 137MB standalone compiled binary (package/bin/codyx) containing an embedded JavaScript CLI application with agent management, upgrade, and uninstall commands referencing opencode[.]ai as a provider. The binary is compiled with the Bun JavaScript runtime. The package has no lifecycle hooks, no npm bin entries, and no executable code files — the binary is inert on installation with no auto-execution mechanism. The package name follows a platform-specific distribution pattern (linux-x64-musl) consistent with infrastructure reserved for a multi-package supply-chain attack: the package serves as a platform-specific dependency that would be consumed by a main package, with no malicious runtime behaviour observable from the static binary content alone.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 11:43 PM
analyzed
Jun 13, 2026, 11:46 PM
weekly installs
530

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.