@copilot-mcp/apex

MAL-2026-12314

npmmalware8/5/2026
Description

Malicious code in @copilot-mcp/apex (npm)

Indicators of Compromise
SHA256 Hashes (13)
1c50752cfe66886c0388a1bc5a637ea28c41556dc55df6a833048a6861f003c4
7c67774146664b91e2a32db292400b675e11ea982d84d600436e0f05c98d106d
c95a10852a2ffe12a9d2b124d014e2092dc2f2d45821ab92feae8cb5308b94ea
a9914f8d0049a694677146664d1ccc97f6c22ad4da6d7516df6b89aca1038d42
c5950e2ea3707a2e1980d40a8dcf3b1d3a6f628e0c645c16681a69f1519f4216
cc4f22ec9d8178ec431e531ad619137c5ad45f16fcec1e8b9d1e5f1dff0a9390
db3a342727ed2f0b264610060bc655650f4593f767f8bfc74f2596fddebeba86
fb0ab81a0d6381793515c0114c6ec09b2c37a4b270bad78cfb524ad658fd39e1
281fff3b92aca15619d6fe90d0937f7de4b64a842606bf075a1df8a1edf1be4f
5ef76eb0d54a5367c418f1796303f7596c3f881664b90495fb16efdf13e1d557
Details
Ecosystemnpm
Attack Typemalware
Published8/5/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001