The @apexacc/cli npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 17 Sept 2026 · npm
@apexacc/cli version 1.5.122 on npm turns off two Windows security features and then downloads a program that takes orders from a remote server. The package is sold as an AI advisor for startup founders. Version 1.5.121 ran the same two commands in plain code and usually failed for lack of rights.
Vigilance found the release on 17 September 2026, eleven hours after it went to npm. No advisory for this package existed in any database at that time. Vigilance published the full analysis as advisory VIGI-001-2026.
What happened
A new release of @apexacc/cli added hidden code that switches off Windows Defender scanning and Smart App Control, then installs a remote-controlled program. The release is 1.5.122. It went live on npm on 17 September 2026 at 08:27 UTC.
It was the fourth release that morning. Version 1.5.120 went up at 08:19:39 and version 1.5.121 went up at 08:26:10. The repository history shows eight commits on the main branch that day. Every one is titled "minor fix". The repository has no pull requests, so no review took place.
The change is small. Version 1.5.121 already ran two commands in plain code. Version 1.5.122 runs the same two commands, but it base64-encodes them and starts them in a hidden PowerShell window that asks Windows for administrator rights. The code comment reads "Windows 11 UAC elevation for SAC disable + exclusion".
When decoded, the two commands do this:
- The first adds a Defender exclusion for the
.apexfolder in the user's home directory. Defender then stops scanning the folder that receives the download. - The second sets a registry value under
HKLM\SYSTEM\CurrentControlSet\Control\CI\Policythat turns off Smart App Control.
The tool then downloads three files from the project's own GitHub releases. The Windows file is 110,948,352 bytes. It sends a POST request to https://vrf.apexaccs.org/api/v1/vrf with the body {"p":"win32"}. The reply has three fields named cmd, exec and args. The program writes them to %TEMP%\_apex_run.ps1 and writes a launcher to %TEMP%\_apex_run.vbs. It then runs the launcher detached and discards the output. The server chooses the command, so it can return a different one on each call.
The same binary sends its AI-copilot traffic to arena.apexaccs.org/api/llm/v1. An API key that a user enters for those features goes through that server. This happens whether or not the backdoor runs.
Affected versions
- @apexacc/cli 1.5.122 and later releases carry the hidden elevation code.
- @apexacc/cli 1.5.121 runs the same two commands in plain code with no request for administrator rights. They usually fail.
- The package had about 3,000 downloads a week when Vigilance published the advisory.
- The attack targets Windows 11. The macOS build ships a helper named
apex-verify-darwinthat contains the samevrf.apexaccs.orgaddress.
On 18 September 2026 the npm package was still installable. Check the current status on npm before you rely on this page.
Indicators of compromise
- Primary server:
https://vrf.apexaccs.org/api/v1/vrf - Second server:
https://arena.apexaccs.org/api/copilot/*andhttps://arena.apexaccs.org/api/llm/v1 - Domain:
apexaccs.org. Namecheap registered it on 8 August 2026. It is one letter longer than the package's own apexacc name. - Files dropped:
%TEMP%\_apex_run.ps1,%TEMP%\_apex_run.vbs,~/.apex/apex-tokenand~/.apex/.key - Windows binary SHA-256:
cc0910a655335297747d06772f3b4aedd92d0f3c0646cb8af585266521129a50 - macOS helper SHA-256:
b0cb369029a7dd7de6510d60caac154a0bd91ad6b9a08d69c90227627743ec71 - Package tarball 1.5.122 SHA-256:
7c43726fcfdf5393854f34886c02ae63d82cc057ae6ab0e7bf05d0b1b9966725 - Accounts: npm
apexaccelerator, GitHubapexfdn - A Defender exclusion for the
.apexfolder, and Smart App Control turned off without your action
How to check
Look for the package in your projects and global installs first. Then look for the dropped files and the Defender exclusion.
npm ls -g @apexacc/cli
npm ls @apexacc/cli
On Windows, check for the folder and for the dropped script. Then list the Defender exclusions.
Test-Path "$env:USERPROFILE\.apex"
Test-Path "$env:TEMP\_apex_run.ps1"
(Get-MpPreference).ExclusionPath
On macOS, check for the folder.
ls -la ~/.apex
You can also catch this kind of change before install. Vigilance compares the old tarball with the new one. For this release, the scan command was vigi diff --old cli-1.5.121.tgz --new cli-1.5.122.tgz. It flagged one file, apex.cjs, because the file now runs a hidden, encoded command that the old version did not run.
What to do now
If you ran @apexacc/cli on Windows 11 after 17 September 2026, treat the machine as exposed. The server can send any command.
- Uninstall the package.
- Delete the
.apexfolder. On Windows it is%USERPROFILE%\.apex. On macOS it is~/.apex. - Turn Smart App Control back on. It is in Windows Security under App & browser control.
- Remove the Defender exclusion for that folder in the Virus & threat protection settings.
- Rotate credentials from a machine you trust. This includes npm tokens and
.npmrccontents, SSH keys, browser-saved passwords and session cookies, crypto wallets, and CI and cloud secrets present on the machine. - If you entered an API key in the tool's AI features, revoke that key.
- Block
apexaccs.orgat your DNS or proxy.
What Vigilance showed
Scanned on 2026-09-18. Exit code 1. The package code was not executed.
vigi files scanned: 4 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED apex.cjs It now runs a hidden, encoded command. It did not before. Coverage: walk finished; 4 files listed, 0 opaque files, 0 unread files or containers. Use --coverage-out <file.json> to save the full lists, including file paths.
Scan version and artifact hashes
Scanner commit: 8c6ac310365de110c491f820b670ac6c1fbfd05e
Scanner SHA-256: f388fd9ca8aea3c6b5491436d1a70d69af5b940aa90c04051afe8178ae3575a4
archive 1.5.1211709b53dde2f5021b65b0f4b5a61efa4069db91743df527e84cc3f820ad1612a
archive 1.5.1227c43726fcfdf5393854f34886c02ae63d82cc057ae6ab0e7bf05d0b1b9966725
Frequently asked questions
What does @apexacc/cli 1.5.122 do?
It starts a hidden administrator PowerShell window on Windows 11. The window adds a Defender exclusion for the .apex folder and turns off Smart App Control. The tool then downloads a program that asks vrf.apexaccs.org for a command and runs the reply.
Is @apexacc/cli 1.5.121 safe?
Not fully. Version 1.5.121 runs the same two commands in plain code with no request for administrator rights, so they usually fail. Vigilance flagged the jump to 1.5.122, where the same intent runs elevated and hidden.
How did Vigilance find the @apexacc/cli attack?
Vigilance compares each npm release with the one before it. It saw that apex.cjs in 1.5.122 runs a hidden, encoded command that the old version did not run. It flagged the release eleven hours after publication, with no advisory in any database.
Sources
More supply chain attacks
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
- axios npm maintainer account takeover 31 Mar 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.