malware
npm
@apexfdn/copilot-mcp
discovered 2026-07-22Payload-free same-operator front package, live on npm since 2026-04-30. Contains no install-time or postinstall malicious code and is the 'advertised' MCP server the dropper's apex.cjs --mcp-stdio path launches to make the install look successful. It is not a safe alternative: it forwards the user's token and extracted document excerpts to the operator's own domain arena.apexfdn.xyz. Treat as attacker-controlled infrastructure. Maintainer email [email protected].
Threat types
data_exfiltration
Malicious versions
- 0.1.0