LWA-2026-5162 confirmed malware

codyx-ai-linux-x64@1.14.42

Malicious code in codyx-ai-linux-x64 (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

codyx-ai-linux-x64 ships a 148MB precompiled Node.js CLI binary (ELF x86-64) in package/bin/codyx. The binary bundles the Node.js/V8/libuv runtime with application logic and is opaque to static analysis — no source code is available for inspection. The package has no lifecycle hooks so the binary does not execute on install, but the same publisher has previously published multiple confirmed-malicious packages under the "cody" namespace. The binary's actual behaviour cannot be verified from static analysis alone.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 11:43 PM
analyzed
Jun 13, 2026, 11:45 PM
weekly installs
549

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.