LWA-2026-6047 confirmed malware

codyx-ai-linux-x64-musl@1.14.42

Malicious code in codyx-ai-linux-x64-musl (npm)

T1195.002 · Compromise Software Supply ChainT1204.002 · Malicious File

Analysis

codyx-ai-linux-x64-musl is a combosquat package that impersonates Sourcegraph's Cody AI assistant by adding "x" to the real product name and mimicking platform-specific binary distribution naming conventions. The package ships a 143MB native binary at ./package/bin/codyx with no source code, no lifecycle hooks, and no documentation or repository verification. The binary is opaque to analysis and its behaviour cannot be determined statically; the package exists to deliver this binary to installers who mistake it for the legitimate Cody AI tooling.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 03:59 PM
analyzed
Jun 27, 2026, 09:25 PM
weekly installs
543

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.