{
  "campaign": {
    "name": "Apex Foundation",
    "slug": "apex-foundation",
    "href": "/ti/campaigns/apex-foundation",
    "description": "Multi-incident npm operation targeting Web3 and crypto founders with a macOS AMOS/Atomic-Stealer infostealer delivered through an npm postinstall dropper and a hosted remote-MCP endpoint. Operator brands itself 'Apex Foundation' / 'Apex Arena' (GitHub org Apex-Foundation, domain apexfdn.xyz). Ran two npm publish-takedown cycles of the same dropper under different scopes (@apexfdn/apex 2026-07-05 to 2026-07-21, then @copilot-mcp/apex 2026-07-22) behind a 3-month aged front package (@apexfdn/copilot-mcp, live since 2026-04-30). Backend is an explicitly multi-tenant FastAPI panel that provisions a subdomain and upload token per campaign, indicating additional incidents under this operator are likely. npm accounts copilotapex and apex-fdn; GitHub user apexfdn; socials Telegram @charlereum / @apex_accelerator, X @AcceleratorApex, Medium @ApexAccelerator, Crunchbase apexfdn.",
    "objective": "Steal crypto wallets, browser credentials, SSH/AWS/Kubernetes credentials, and the macOS login Keychain from Web3 founders and developers, and maintain a standing backdoor via a C2-polling LaunchAgent.",
    "aliases": [
      "Apex Arena",
      "apexfdn"
    ],
    "discovered_at": "2026-07-22"
  },
  "packages": [
    {
      "ecosystem": "npm",
      "name": "@copilot-mcp/apex",
      "href": "/ti/packages/npm/@copilot-mcp/apex",
      "threat_types": [
        "credential_stealer",
        "data_exfiltration",
        "c2_agent",
        "persistence"
      ],
      "versions": [
        "1.0.0",
        "1.0.19",
        "1.0.21",
        "1.0.22"
      ]
    },
    {
      "ecosystem": "npm",
      "name": "@apexfdn/apex",
      "href": "/ti/packages/npm/@apexfdn/apex",
      "threat_types": [
        "credential_stealer",
        "data_exfiltration",
        "c2_agent",
        "persistence"
      ],
      "versions": [
        "1.0.0"
      ]
    },
    {
      "ecosystem": "npm",
      "name": "@apexfdn/copilot-mcp",
      "href": "/ti/packages/npm/@apexfdn/copilot-mcp",
      "threat_types": [
        "data_exfiltration"
      ],
      "versions": [
        "0.1.0"
      ]
    }
  ],
  "indicators": [
    {
      "kind": "url",
      "value": "https://arena.apexfdn.xyz/api/copilot/mcp",
      "href": "/ti/ioc/url/url-f5ee173a3d2a",
      "context": "Hosted remote-MCP endpoint reached with a Bearer token. No-install infection vector that sends tokens to attacker infrastructure without any package install."
    },
    {
      "kind": "github_repo",
      "value": "Apex-Foundation/copilot-mcp",
      "href": "/ti/ioc/github_repo/github_repo-1ee17eff897b",
      "context": "The advertised (clean) source in the dropper's repository field; benign TypeScript that misdirects reviewers away from the real binary source Apex-Foundation/copilot."
    },
    {
      "kind": "email",
      "value": "arena@apexfdn.xyz",
      "href": "/ti/ioc/email/arena@apexfdn.xyz",
      "context": "npm maintainer email for the dropper (@copilot-mcp/apex / @apexfdn/apex)."
    },
    {
      "kind": "email",
      "value": "contact@apexfdn.xyz",
      "href": "/ti/ioc/email/contact@apexfdn.xyz",
      "context": "npm maintainer email for the front package @apexfdn/copilot-mcp. Same apexfdn.xyz domain as the dropper maintainer, linking the two scopes to one operator."
    },
    {
      "kind": "email",
      "value": "chefkecharlie@gmail.com",
      "href": "/ti/ioc/email/chefkecharlie@gmail.com",
      "context": "Operator-associated email (ties to Telegram @charlereum)."
    },
    {
      "kind": "domain",
      "value": "apexfdn.xyz",
      "href": "/ti/ioc/domain/apexfdn.xyz",
      "context": "Operator brand domain ('Apex Foundation'). Anchors the npm scope @apexfdn and maintainer emails."
    },
    {
      "kind": "domain",
      "value": "docs.apexfdn.xyz",
      "href": "/ti/ioc/domain/docs.apexfdn.xyz",
      "context": "Operator documentation host in the apexfdn.xyz family."
    },
    {
      "kind": "domain",
      "value": "update.apex-arena-router.com",
      "href": "/ti/ioc/domain/update.apex-arena-router.com",
      "context": "Primary C2 / exfil host. Resolves to 172.93.185.150 (xTom GmbH, AS3214, Frankfurt). Caddy reverse proxy in front of Uvicorn/FastAPI, wildcard Let's Encrypt cert for *.apex-arena-router.com, /openapi.json exposed unauthenticated. Serves loader.sh + payload.enc, receives exfil uploads, and answers the 60s persistence ping."
    },
    {
      "kind": "url",
      "value": "https://update.apex-arena-router.com/payload.enc",
      "href": "/ti/ioc/url/url-b22340527fd2",
      "context": "AES-256-CBC encrypted macOS stealer payload fetched by loader.sh, decrypted in memory (key = upload token) and piped to osascript. Never written to disk as a separate file."
    },
    {
      "kind": "ipv4",
      "value": "172.93.185.150",
      "href": "/ti/ioc/ipv4/172.93.185.150",
      "context": "C2 server IP. xTom GmbH (AS3214), Frankfurt am Main, Germany."
    },
    {
      "kind": "github_repo",
      "value": "Apex-Foundation/copilot",
      "href": "/ti/ioc/github_repo/github_repo-7bd1f158efc7",
      "context": "Weaponized fork of can1357/oh-my-pi that hosts the downloaded release binaries (apex-linux-x64, apex-darwin-arm64/x64, apex-windows-x64, apex-helper-darwin, apex-auth-darwin, pi_natives.win32-x64-baseline.node). install.cjs fetches from its v1.0.0 release tag; assets are swappable server-side. Still live after both npm takedowns."
    },
    {
      "kind": "file_path",
      "value": "/tmp/osalogging.zip",
      "href": "/ti/ioc/file_path/file_path-2b800a65a3b4",
      "context": "Staged stolen-data archive (ditto -c -k) uploaded over chunked HTTPS PUT, then rm -f'd for anti-forensics."
    },
    {
      "kind": "file_path",
      "value": "~/Library/LaunchAgents/com.system.notifications.agent.plist",
      "href": "/ti/ioc/file_path/file_path-3c9fd16e0017",
      "context": "Persistence LaunchAgent (label com.system.notifications.agent, StartInterval 60s) that polls /v1/agent/ping on the C2 host every 60 seconds for follow-on commands."
    },
    {
      "kind": "file_path",
      "value": "~/Library/Application Support/System/System Notifications.app",
      "href": "/ti/ioc/file_path/file_path-ae14b1053584",
      "context": "Fake app bundle (bundle ID com.system.notifications.helper.bld013) dropped and registered via lsregister; masquerades as macOS 'System Notifications'."
    },
    {
      "kind": "file_path",
      "value": "/tmp/sync<random>/",
      "href": "/ti/ioc/file_path/file_path-17a6719b605a",
      "context": "Stealer staging directory where browser data, wallets, keys, and Keychain are collected before archiving; cleared after upload."
    },
    {
      "kind": "sha1",
      "value": "233f90180b529aa32911901e5222e9ed9c3cd24c",
      "href": "/ti/ioc/sha1/233f90180b529aa32911901e5222e9ed9c3cd24c",
      "context": "npm tarball SHA1 for @copilot-mcp/apex@1.0.0 (inline curl|zsh launcher variant)."
    },
    {
      "kind": "sha1",
      "value": "3b9a880ae4e1c5b7bbd68e118a1c3c8b592f7bfb",
      "href": "/ti/ioc/sha1/3b9a880ae4e1c5b7bbd68e118a1c3c8b592f7bfb",
      "context": "npm tarball SHA1 for @copilot-mcp/apex@1.0.19 (compiled apex-helper-darwin launcher variant)."
    },
    {
      "kind": "sha256",
      "value": "ecd1113fae1ede9869afd9d1af612bab7f1a2054e5c45a346e18c107c22b9164",
      "href": "/ti/ioc/sha256/ecd1113fae1ede9869afd9d1af612bab7f1a2054e5c45a346e18c107c22b9164",
      "context": "payload.enc, the AES-256-CBC encrypted 707-line AMOS-family AppleScript stealer. Decrypts with the upload token 5c6f24c905ae3883355a26fceac3dda0d0dfe67ba8e1220ebe784a29544c6ee4 (SHA-256 key derivation); that same value doubles as the X-Upload-Token in every exfil request."
    },
    {
      "kind": "domain",
      "value": "arena.apexfdn.xyz",
      "href": "/ti/ioc/domain/arena.apexfdn.xyz",
      "context": "Operator front/dashboard host (arena.apexfdn.xyz/dashboard/copilot). Hosts the remote-MCP endpoint and receives the @apexfdn/copilot-mcp front package's forwarded tokens and document excerpts."
    }
  ],
  "ttps": [
    {
      "name": "Command and Scripting Interpreter: AppleScript",
      "mitre_attack_id": "T1059.002",
      "href": "/ti/ttps/T1059.002"
    },
    {
      "name": "Command and Scripting Interpreter: Unix Shell",
      "mitre_attack_id": "T1059.004",
      "href": "/ti/ttps/T1059.004"
    },
    {
      "name": "Input Capture: GUI Input Capture",
      "mitre_attack_id": "T1056.002",
      "href": "/ti/ttps/T1056.002"
    },
    {
      "name": "Credentials from Password Stores: Keychain",
      "mitre_attack_id": "T1555.001",
      "href": "/ti/ttps/T1555.001"
    },
    {
      "name": "Unsecured Credentials: Credentials In Files",
      "mitre_attack_id": "T1552.001",
      "href": "/ti/ttps/T1552.001"
    },
    {
      "name": "Steal Web Session Cookie",
      "mitre_attack_id": "T1539",
      "href": "/ti/ttps/T1539"
    },
    {
      "name": "Create or Modify System Process: Launch Agent",
      "mitre_attack_id": "T1543.001",
      "href": "/ti/ttps/T1543.001"
    },
    {
      "name": "Application Layer Protocol: Web Protocols",
      "mitre_attack_id": "T1071.001",
      "href": "/ti/ttps/T1071.001"
    },
    {
      "name": "Exfiltration Over C2 Channel",
      "mitre_attack_id": "T1041",
      "href": "/ti/ttps/T1041"
    },
    {
      "name": "Obfuscated Files or Information",
      "mitre_attack_id": "T1027",
      "href": "/ti/ttps/T1027"
    },
    {
      "name": "Masquerading",
      "mitre_attack_id": "T1036",
      "href": "/ti/ttps/T1036"
    },
    {
      "name": "System Information Discovery",
      "mitre_attack_id": "T1082",
      "href": "/ti/ttps/T1082"
    },
    {
      "name": "Automated Collection",
      "mitre_attack_id": "T1119",
      "href": "/ti/ttps/T1119"
    }
  ],
  "related_campaigns": [],
  "reports": [
    {
      "title": "@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown",
      "url": "https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer",
      "published_at": "2026-07-22"
    }
  ]
}