malware
npm
@apexfdn/apex
discovered 2026-07-22Original postinstall dropper, same code later re-published as @copilot-mcp/apex. First published 2026-07-05 and shipped 34 versions (1.0.0 through ~1.0.32) over roughly two and a half weeks before the npm security team removed it on 2026-07-21 for malicious code and replaced it with a 0.0.1-security placeholder. Delivers the same macOS AMOS infostealer chain as the re-publish.
Threat types
credential_stealer data_exfiltration c2_agent persistence
Malicious versions
- 1.0.0