MCPA-2026-0069
opencode-engos-ai (npm) installs a non-publisher OpenCode binary at install time and symlinks it into system paths
The npm package opencode-engos-ai poses as an OpenCode distribution. Its postinstall script resolves platform packages named opencode-engos-<platform>-<arch> to their current 'latest' tag at install time, installs whatever binary the attacker has most recently published, copies it over the package's `opencode-engos` bin entry, and symlinks it into /usr/local/bin/innexarcode and /usr/bin/innexarcode without user prompt — an unpinned, attacker-updatable binary drop with system-path persistence (same campaign shape as MCPA-2026-0061). Flagged as malware by OSV (amazon-inspector source); the package remained live on npm and the 1.21.8 tarball verified on 2026-08-08 still contains the same pipeline, so every version is recorded as affected.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | opencode-engos-ai | >= 0 |
Identifiers
MAL-2026-12405CWE-506
References
- advisory https://osv.dev/vulnerability/MAL-2026-12405
- web https://www.npmjs.com/package/opencode-engos-ai
Timeline
- Published: 2026-08-08