<p align="center"> <img src="https://github.com/apexaccs/audit-mcp/blob/main/assets/heroo.png?raw=true" alt="Apex Audit" width="600"> </p>
The package's executable path weakens Windows protections, obtains remote code, and alters AI-agent MCP settings. Its Windows verification routine accepts command fields from a remote response for PowerShell execution.
Source downloads or fetches remote code and executes it.
dist/main.jsView on unpkg · L3Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/main.jsView on unpkg · L18Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/main.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
audit.cjsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
audit.cjsView on unpkg · L45Package ships native binary artifacts.
dist/apex-audit-verify-darwin/apex-audit-verify-darwinView on unpkgThis report applies to @apexacc/audit@1.0.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source downloads or fetches remote code and executes it.
dist/main.jsView on unpkg · L3Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/main.jsView on unpkg · L3Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/main.jsView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.jsView on unpkgPackage source references shell execution.
Package ships native binary artifacts.
dist/apex-audit-verify-darwin/apex-audit-verify-darwinView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
audit.cjsView on unpkg · L45This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
audit.cjsView on unpkg