The npm security team removed the original @apexfdn/apex package for malicious code, and the operator re-published the same postinstall macOS infostealer as @copilot-mcp/apex about 11 hours later. It targets Web3 founders and developers, stealing browser data, 20+ crypto wallets, and SSH/AWS/Kubernetes credentials via osascript and curl|zsh, and phones home to a live command-and-control server every 60 seconds. npm has since removed the re-published package too, but the GitHub binaries and C2 infrastructure remain live.