Apex Foundation

discovered 2026-07-22

Multi-incident npm operation targeting Web3 and crypto founders with a macOS AMOS/Atomic-Stealer infostealer delivered through an npm postinstall dropper and a hosted remote-MCP endpoint. Operator brands itself 'Apex Foundation' / 'Apex Arena' (GitHub org Apex-Foundation, domain apexfdn.xyz). Ran two npm publish-takedown cycles of the same dropper under different scopes (@apexfdn/apex 2026-07-05 to 2026-07-21, then @copilot-mcp/apex 2026-07-22) behind a 3-month aged front package (@apexfdn/copilot-mcp, live since 2026-04-30). Backend is an explicitly multi-tenant FastAPI panel that provisions a subdomain and upload token per campaign, indicating additional incidents under this operator are likely. npm accounts copilotapex and apex-fdn; GitHub user apexfdn; socials Telegram @charlereum / @apex_accelerator, X @AcceleratorApex, Medium @ApexAccelerator, Crunchbase apexfdn.

Objective

Steal crypto wallets, browser credentials, SSH/AWS/Kubernetes credentials, and the macOS login Keychain from Web3 founders and developers, and maintain a standing backdoor via a C2-polling LaunchAgent.

Packages

Indicators

Techniques

Read the full analysis →