malware npm

@apexfdn/apex

discovered 2026-07-22

Original postinstall dropper, same code later re-published as @copilot-mcp/apex. First published 2026-07-05 and shipped 34 versions (1.0.0 through ~1.0.32) over roughly two and a half weeks before the npm security team removed it on 2026-07-21 for malicious code and replaced it with a 0.0.1-security placeholder. Delivers the same macOS AMOS infostealer chain as the re-publish.

Threat types

credential_stealer data_exfiltration c2_agent persistence

Malicious versions

  • 1.0.0

Campaigns

Read the full analysis →