MAL-2026-11997
Malicious code in sextant-cli-darwin-arm64 (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (395a381c321ebe4cfb276cf354d97d45a8fde8f9882b2d31471a7d6ac5e74229) The tarball ships a Mach-O Go binary at bin/sxt built from the module github.com/ddos798/claude_control. The binary statically links a WebSocket client (github.com/coder/websocket), a PTY library (github.com/creack/pty), and shell invocations of /bin/sh and /bin/bash, and it connects to a hardcoded C2 endpoint at wss://relay.sextant.top. This is a network-source-to-PTY-sink dataflow: a remote operator at relay.sextant.top can drive an interactive shell on the host running sxt. The binary additionally contains a regex targeting Anthropic API keys (sk-ant-[a-z0-9]+-[A-Za-z0-9_-]{40,}), reads CLAUDE_CONFIG_DIR and ~/.claude, and reaches https://api.anthropic.com/v1/models — targeted theft of Claude credentials from the host. At startup the binary fingerprints the host via http://ip-api.com/json/ (public IP, country, city, timezone) plus os.Hostname and POSTs to https://relay.sextant.top/install. The package mimics the naming convention of a platform-specific optional dependency (like @esbuild/darwin-arm64) so a parent sextant-cli package pulls it as a mandatory arm64 sub-binary, and the package.json license URL points at github.com/ddos798/claude_control — the upstream module is self-describing.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for sextant-cli-darwin-arm64 (npm). Pin to a known-safe version or switch to an alternative.