Multi-incident npm operation targeting Web3 and crypto founders with a macOS AMOS/Atomic-Stealer infostealer delivered through an npm postinstall dropper and a hosted remote-MCP endpoint. Operator brands itself 'Apex Foundation' / 'Apex Arena' (GitHub org Apex-Foundation, domain apexfdn.xyz). Ran two npm publish-takedown cycles of the same dropper under different scopes (@apexfdn/apex 2026-07-05 to 2026-07-21, then @copilot-mcp/apex 2026-07-22) behind a 3-month aged front package (@apexfdn/copilot-mcp, live since 2026-04-30). Backend is an explicitly multi-tenant FastAPI panel that provisions a subdomain and upload token per campaign, indicating additional incidents under this operator are likely. npm accounts copilotapex and apex-fdn; GitHub user apexfdn; socials Telegram @charlereum / @apex_accelerator, X @AcceleratorApex, Medium @ApexAccelerator, Crunchbase apexfdn.
Objective
Steal crypto wallets, browser credentials, SSH/AWS/Kubernetes credentials, and the macOS login Keychain from Web3 founders and developers, and maintain a standing backdoor via a C2-polling LaunchAgent.
Packages
Indicators
- url https://arena.apexfdn.xyz/api/copilot/mcpuses
- github_repo Apex-Foundation/copilot-mcpuses
- email [email protected]indicates
- email [email protected]indicates
- email [email protected]indicates
- domain apexfdn.xyzindicates
- domain docs.apexfdn.xyzindicates
- domain update.apex-arena-router.comcommunicates-with
- url https://update.apex-arena-router.com/payload.enccommunicates-with
- ipv4 172.93.185.150communicates-with
- github_repo Apex-Foundation/copilotcommunicates-with
- file_path /tmp/osalogging.zipdrops
- file_path ~/Library/LaunchAgents/com.system.notifications.agent.plistdrops
- file_path ~/Library/Application Support/System/System Notifications.appdrops
- file_path /tmp/sync<random>/drops
- sha1 233f90180b529aa32911901e5222e9ed9c3cd24cindicates
- sha1 3b9a880ae4e1c5b7bbd68e118a1c3c8b592f7bfbindicates
- sha256 ecd1113fae1ede9869afd9d1af612bab7f1a2054e5c45a346e18c107c22b9164indicates
- domain arena.apexfdn.xyzexfiltrates-to
Techniques
- ttp T1059.002 Command and Scripting Interpreter: AppleScriptuses
- ttp T1059.004 Command and Scripting Interpreter: Unix Shelluses
- ttp T1056.002 Input Capture: GUI Input Captureuses
- ttp T1555.001 Credentials from Password Stores: Keychainuses
- ttp T1552.001 Unsecured Credentials: Credentials In Filesuses
- ttp T1539 Steal Web Session Cookieuses
- ttp T1543.001 Create or Modify System Process: Launch Agentuses
- ttp T1071.001 Application Layer Protocol: Web Protocolsuses
- ttp T1041 Exfiltration Over C2 Channeluses
- ttp T1027 Obfuscated Files or Informationuses
- ttp T1036 Masqueradinguses
- ttp T1082 System Information Discoveryuses
- ttp T1119 Automated Collectionuses