Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@copilot-mcp/apexnpm

@copilot-mcp/apex is a confirmed malicious npm package (MAL-2026-12314) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @copilot-mcp/apex (npm)

MAL-2026-12314
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @copilot-mcp/apex

What this malware does

install.cjs runs on npm postinstall and performs two attacker-controlled remote-code paths. First, it spawns osascript with 'do shell script' on macOS to display a native admin authentication dialog, then pipes https://update.apex-arena-router.com/loader.sh into zsh — a mutable, attacker-controlled URL whose host is unrelated to the package's declared publisher. Second, it downloads an OS-specific 'apex' binary from the github.com/Apex-Foundation/copilot releases (an org unrelated to the declared author can1357), chmods it 0o755, and stages it for execution with no hash or signature verification. The package is a hollow lure: package.json declares main./src/index.ts and ~150 export subpaths, but the tarball ships no src/ directory. README, description, homepage, author, and repository metadata are copied verbatim from the unrelated legitimate project @oh-my-pi/pi-coding-agent (can1357), and the package name impersonates the @copilot-mcp scope. The only shipped code is install.cjs (the dropper) and apex.cjs (which invokes the downloaded binary). Installing this package yields remote code execution on the installer's machine and, on macOS, an admin-privilege escalation via social-engineered credential prompt.

Malicious versions

12 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.161.0.171.0.22

Indicators of compromise (SHA-256)

1c50752cfe66886c0388a1bc5a637ea28c41556dc55df6a833048a6861f003c4
7c67774146664b91e2a32db292400b675e11ea982d84d600436e0f05c98d106d
c95a10852a2ffe12a9d2b124d014e2092dc2f2d45821ab92feae8cb5308b94ea
a9914f8d0049a694677146664d1ccc97f6c22ad4da6d7516df6b89aca1038d42
c5950e2ea3707a2e1980d40a8dcf3b1d3a6f628e0c645c16681a69f1519f4216
cc4f22ec9d8178ec431e531ad619137c5ad45f16fcec1e8b9d1e5f1dff0a9390
db3a342727ed2f0b264610060bc655650f4593f767f8bfc74f2596fddebeba86
fb0ab81a0d6381793515c0114c6ec09b2c37a4b270bad78cfb524ad658fd39e1
281fff3b92aca15619d6fe90d0937f7de4b64a842606bf075a1df8a1edf1be4f
5ef76eb0d54a5367c418f1796303f7596c3f881664b90495fb16efdf13e1d557
6c21f6b832569e73d76688cd181daa0821b94f00d41205fc1ba2003671c8946c
7be50b386dc90979307b118d6b733815cca1c32994688af4e00f80931c45fc6c

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @copilot-mcp/apex (12 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @copilot-mcp/apex across your stack and pipelines.

  2. If you installed it — respond

    @copilot-mcp/apex is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @copilot-mcp/apex was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @copilot-mcp/apex before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @copilot-mcp/apex on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, and 4 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-014678IN-MAL-2026-014670IN-MAL-2026-014668IN-MAL-2026-014663IN-MAL-2026-014673IN-MAL-2026-014671IN-MAL-2026-014669IN-MAL-2026-014672IN-MAL-2026-014723IN-MAL-2026-014665IN-MAL-2026-014666IN-MAL-2026-014680

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @copilot-mcp/apex-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore