@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown The npm package @copilot-mcp/apex is a postinstall dropper that installs a macOS infostealer on any machine that runs npm install or npx @copilot-mcp/apex, according to a security analysis. The package, which targets Web3 and crypto founders with a fake AI-advisor pitch, was re-published under a new scope 11 hours after npm's security team removed the original dropper @apexfdn/apex. The stealer phishes the login password, harvests browser credentials, 20+ crypto wallets, the login Keychain, Telegram, and shell history, and exfiltrates the data over HTTPS. @copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown Table of Contents Resolution / Status:The npm security team already removed the original dropper, @apexfdn/apex , and replaced it with a 0.0.1-security placeholder that states outright the package “contained malicious code.” The operator re-published the same dropper under a new scope, @copilot-mcp/apex , about 11 hours later, and has since pushed 20+ versions 1.0.0 through 1.0.22 in about 8 hours. At the time of writing, @copilot-mcp/apex remains live on npm and is still being updated. TL;DR @copilot-mcp/apex is a postinstall dropper that installs a macOS infostealer on any machine that runs npm install or npx @copilot-mcp/apex . It is not a first attempt. npm’s security team already removed the same code once, published under the name @apexfdn/apex , and the operator answered by moving the dropper to a new scope rather than stopping. The campaign runs three npm-adjacent surfaces built by one operator: | Package / vector | Role | Status | |---|---|---| @apexfdn/apex | Original postinstall dropper | Removed by npm; now a 0.0.1-security placeholder | @copilot-mcp/apex | Same dropper, re-published under a new scope | Live, versions 1.0.0 - 1.0.22 | @apexfdn/copilot-mcp | The advertised MCP server “diligence tools” | Payload-free, but same-operator front | arena.apexfdn.xyz/api/copilot/mcp | Hosted remote MCP endpoint Bearer token | No-install vector, sends tokens to attacker infra | On macOS, the dropper’s second stage decrypts and runs an AppleScript payload through osascript . The decrypted payload is a 707-line AMOS-family stealer: it phishes the login password through a fake system prompt, then harvests browser credentials, 20+ crypto wallets, the login Keychain, Telegram, and shell history into /tmp/osalogging.zip and uploads it over chunked HTTPS PUT to attacker infrastructure. The lure targets Web3 and crypto founders with a “free LLM credits” AI-advisor pitch. Impact: - Runs on npm install or npx , with no user interaction beyond the install itself - Downloads a ~120-150MB platform binary from a GitHub repo different from the one the package advertises as its source, pinned to a static release tag so the payload can be swapped server-side without a new npm publish - On macOS, phishes the login password through a fake system dialog, then steals browser credentials and cookies, 20+ crypto wallets, the login Keychain, Telegram, and shell history, installs a LaunchAgent for persistence, and exfiltrates the archive at /tmp/osalogging.zip over HTTPS - Already survived one npm takedown: removed as @apexfdn/apex , live again as @copilot-mcp/apex within 11 hours, and still iterating - On Linux and Windows the macOS theft path does not fire, but postinstall still executes an unreviewed downloaded binary; the campaign is not safe on any platform Indicators of Compromise IoC : | Indicator | Value | |---|---| | npm package malicious, live | @copilot-mcp/apex , versions 1.0.0 - 1.0.22 | | npm package malicious, removed by npm | @apexfdn/apex , now a 0.0.1-security placeholder | | npm package same-operator front | @apexfdn/copilot-mcp | | Hosted remote-MCP endpoint | hxxps://arena . apexfdn . xyz/api/copilot/mcp Bearer token | | C2 / exfil domain | update . apex-arena-router . com | | C2 paths | /loader.sh, /payload.enc, /v1/asset/