malware npm

@copilot-mcp/apex

discovered 2026-07-22

Postinstall dropper that installs a macOS AMOS-family infostealer. Byte-identical re-publish of @apexfdn/apex under a new scope about 11 hours after npm removed the original. install.cjs downloads a 120-150MB platform binary (repackaged can1357/oh-my-pi fork) from Apex-Foundation/copilot pinned to release tag v1.0.0; macOS branch runs loader.sh (curl|zsh / osascript) which AES-256-CBC decrypts payload.enc in memory and pipes it to osascript. 20+ versions (1.0.0-1.0.22+) shipped in ~8h on 2026-07-22 A/B-testing the macOS launcher; removed by npm same day.

Threat types

credential_stealer data_exfiltration c2_agent persistence

Malicious versions

  • 1.0.0
  • 1.0.19
  • 1.0.21
  • 1.0.22

Campaigns

Indicators

Techniques

Read the full analysis →