OpenSSF/OSV advisory MAL-2026-12314 confirms this npm version as malicious. install.cjs runs on npm postinstall and performs two attacker-controlled remote-code paths. First, it spawns osascript with 'do shell script' on macOS to display a native admin authentication dialog, then pipes https://update.apex-arena-router.com/loader.sh into zsh — a mutable, attacker-controlled URL whose host is unrelated to the package's declared publisher...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source invokes a package manager install command at runtime.
apex.cjsView on unpkg · L15Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
install.cjsView on unpkg · L4Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source invokes a package manager install command at runtime.
apex.cjsView on unpkg · L15Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
install.cjsView on unpkg · L4