LWA-2026-5162 confirmed malware
codyx-ai-linux-x64@1.14.42
Malicious code in codyx-ai-linux-x64 (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
codyx-ai-linux-x64 ships a 148MB precompiled Node.js CLI binary (ELF x86-64) in package/bin/codyx. The binary bundles the Node.js/V8/libuv runtime with application logic and is opaque to static analysis — no source code is available for inspection. The package has no lifecycle hooks so the binary does not execute on install, but the same publisher has previously published multiple confirmed-malicious packages under the "cody" namespace. The binary's actual behaviour cannot be verified from static analysis alone.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 11:43 PM
- analyzed
- Jun 13, 2026, 11:45 PM
- weekly installs
- 549
Related advisories
- codyx-ai-linux-x64-baseline@1.14.42
- simple-auth-basic@2.0.2
- signature-transaction@1.1.0
- sftc-advance-components@0.9.9
- session-exp@1.3.20
- sentrykit@30.0.0
- seed-to-private@1.0.1
- search-reservation@55.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.