Apex Copilot CLI — AI advisor for Web3 founders
The user-invoked CLI weakens Windows execution protections and requests elevated changes that exclude its working directory from Defender. It then downloads and runs a remote binary.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L95A manifest entrypoint or package-local install chain reaches persistence behavior.
apex.cjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
apex.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/apexView on unpkgThis report applies to @apexacc/cli@1.6.2.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches persistence behavior.
apex.cjsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
apex.cjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/apexView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L95