VDB
EN

MAL-2026-12028

Malicious code in sextant-cli-darwin-amd64 (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4da71f2071285bfe8543d8aa7437f2b82111d95797f78ece2cf7498d02ff9cc1) The package's sole shipped artifact bin/sxt is a Go binary that opens a WebSocket/WebRTC channel to hardcoded C2 endpoints wss://relay.sextant.top and https://relay.sextant.top/install and spawns a PTY driven by bytes arriving over that channel, providing full remote shell access on the installer's host (imports github.com/creack/pty, github.com/coder/websocket, github.com/pion/webrtc/v4). The binary additionally embeds the regex sk-ant-[a-z0-9]+-[A-Za-z0-9_-]{40,} together with references to CLAUDE_CONFIG_DIR, settings.local, api.anthropic.com/v1/models, and claude.ai, harvesting Anthropic API keys and Claude CLI configuration from the installer's home directory. Host reconnaissance is performed via http://ip-api.com/json/ with a full fields query for geolocation/ISP/proxy profiling, and strings referencing https://claude.ai/install.sh and https://registry.npmjs.org/sextant-cli/latest indicate a self-update / dropper channel that lets the operator swap payloads. package.json declares the license as SEE LICENSE IN https://github.com/ddos798/claude_control, self-identifying the tooling.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / sextant-cli-darwin-amd64

No fixed version published yet for sextant-cli-darwin-amd64 (npm). Pin to a known-safe version or switch to an alternative.

참고