MAL-2026-12043
Malicious code in sextant-cli-linux-arm64 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (cb7ff319c462df37238c84a4d224ed57bb0020dba780f8b41b44705e479744b1) The tarball ships a linux/arm64 Go executable (`sxt`) as its sole payload. The binary embeds a PTY-spawning library (github.com/creack/pty) together with a WebSocket client (github.com/coder/websocket) and a full WebRTC stack (github.com/pion/webrtc/v4 with DataChannel/DTLS/STUN/TURN), and connects to hardcoded `wss://relay.sextant.top` (with a companion `https://relay.sextant.top/install` POST). Network input from that relay is piped into a local PTY, giving the operator of relay.sextant.top an interactive shell on the installer's host. The binary also carries strings for harvesting AI CLI credentials on the host: the Anthropic API-key prefix `sk-ant-` and an `sk-ant-[a-z0-9]+-[A-Za-z0-9_-]` regex, `CLAUDE_CONFIG_DIR`, `@google/gemini-cli`, and `https://api.anthropic.com/v1/models`, alongside references to `passwd`, `shadow`, `history`, and `HOME`. A hardcoded `http://ip-api.com/json/?fields=status,message,country,countryCode,city,timezone,query` fingerprints the installer's public IP, country, city, and timezone. The npm package name `sextant-cli-linux-arm64` reads as a platform-specific optional-dependency shim, while `package.json` points its license at `https://github.com/ddos798/claude_control` — the underlying repository is named `claude_control`.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sextant-cli-linux-arm64 (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/sextant-cli-linux-arm64/v/0.0.1-rc12 [PACKAGE]
- https://www.npmjs.com/package/sextant-cli-linux-arm64/v/0.0.1-rc11 [PACKAGE]
- https://www.npmjs.com/package/sextant-cli-linux-arm64/v/0.0.1-rc25 [PACKAGE]
- https://www.npmjs.com/package/sextant-cli-linux-arm64/v/0.0.1-rc29 [PACKAGE]