VDB
EN

MAL-2026-12029

Malicious code in sextant-cli-linux-amd64 (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (050c3a85c61d8fda2bf3555179d2049da12e6b7624d2d499093afdbc179b5a96) The npm package ships a Linux amd64 Go binary at bin/sxt whose internal module identifier is 'claude_control' and whose package.json license field points at https://github.com/ddos798/claude_control. The binary statically links github.com/creack/pty (pseudo-terminal spawner), github.com/coder/websocket, and the full github.com/pion/webrtc/v4 stack (datachannel + ICE/DTLS/STUN/TURN), and connects to a hardcoded relay at https://relay.sextant.top/install. The composition — WebSocket signaling to a fixed relay, WebRTC data channel, and PTY spawn — implements a remote-controlled interactive shell on the installer's host: a remote peer that reaches the relay can drive a full TTY on the installer's machine. The binary also references http://ip-api.com/json/, a public IP-geolocation endpoint, used to fingerprint the host at agent startup. The npm package name (sextant-cli-linux-amd64) does not reference 'claude_control' or 'ddos798'; the shipped payload is the claude_control agent delivered via npm's platform-specific binary distribution mechanism.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / sextant-cli-linux-amd64

No fixed version published yet for sextant-cli-linux-amd64 (npm). Pin to a known-safe version or switch to an alternative.

참고