Malicious code in @ccfly/setup-darwin-x64 (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (409d11825a61bed068425296e83dcc0c87427579f7b5d724ec52e5e87465f2b5) The package ships a prebuilt darwin/x64 Mach-O binary containing a Go agent (module github.com/ccfly/rescue) that, when executed, connects to a hardcoded remote broker at cc.hn / ccfly over WebSocket (ws://ccfly, wss://, https://cc.hn) using github.com/gorilla/websocket, spawns a pseudo-terminal via github.com/creack/pty, and pipes the WebSocket stream into that PTY. Symbols include agent.serve, agent.startPTY, agent.waitAuthorized, agent.wsBase and unixPTY.Read/Write/Resize/Close, giving the remote party interactive shell control of the host. A second stage (setup.downloadCcfly, setup.fetchAndExtract, setup.npmTarballURL, setup.extractFromTarGz, setup.runCcflyInstall, setup.redeemEnrollToken, setup.(*brokerClient).escalateToRescue, with a rodata reference to https://registry.npmjs.org) fetches and executes a further ccfly npm tarball after the broker approves an enrollment token — the additional code executed on the host is chosen by the remote broker, not the installer. The binary also inspects shell RC files and /etc/hosts (setup.scanShellProfilesForProxy, setup.checkProxyResidue, setup.checkHostsResidue, setup.runEnvChecks, setup.envReport) and POSTs an environment report back to the broker (setup.(*brokerClient).post; rodata latest.zshrc, export.ccfly).
AI Analysis
Technical Summary
The @ccfly/setup-darwin-x64 npm package (version 0.1.7) includes a Mach-O binary that runs a Go agent connecting to a hardcoded remote broker over WebSocket. The agent spawns a pseudo-terminal and pipes the WebSocket stream into it, granting the remote party interactive shell access. The binary inspects local shell RC files and /etc/hosts, reporting environment details back to the broker. It also supports a second stage where, upon broker approval, it downloads and executes additional npm tarballs with arbitrary code chosen by the attacker. This design allows persistent and flexible remote control of the infected host.
Potential Impact
Successful execution of this package results in full remote shell access to the affected macOS host, enabling arbitrary command execution by the attacker. The attacker can also gather environment information and dynamically deploy further malicious payloads, significantly compromising host confidentiality, integrity, and availability.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should avoid installing or using @ccfly/setup-darwin-x64 version 0.1.7. Remove any installations of this package and audit affected systems for signs of compromise. Monitor for connections to the indicated broker domains and consider network-level blocking of these endpoints. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in @ccfly/setup-darwin-x64 (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (409d11825a61bed068425296e83dcc0c87427579f7b5d724ec52e5e87465f2b5) The package ships a prebuilt darwin/x64 Mach-O binary containing a Go agent (module github.com/ccfly/rescue) that, when executed, connects to a hardcoded remote broker at cc.hn / ccfly over WebSocket (ws://ccfly, wss://, https://cc.hn) using github.com/gorilla/websocket, spawns a pseudo-terminal via github.com/creack/pty, and pipes the WebSocket stream into that PTY. Symbols include agent.serve, agent.startPTY, agent.waitAuthorized, agent.wsBase and unixPTY.Read/Write/Resize/Close, giving the remote party interactive shell control of the host. A second stage (setup.downloadCcfly, setup.fetchAndExtract, setup.npmTarballURL, setup.extractFromTarGz, setup.runCcflyInstall, setup.redeemEnrollToken, setup.(*brokerClient).escalateToRescue, with a rodata reference to https://registry.npmjs.org) fetches and executes a further ccfly npm tarball after the broker approves an enrollment token — the additional code executed on the host is chosen by the remote broker, not the installer. The binary also inspects shell RC files and /etc/hosts (setup.scanShellProfilesForProxy, setup.checkProxyResidue, setup.checkHostsResidue, setup.runEnvChecks, setup.envReport) and POSTs an environment report back to the broker (setup.(*brokerClient).post; rodata latest.zshrc, export.ccfly).
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @ccfly/setup-darwin-x64 npm package (version 0.1.7) includes a Mach-O binary that runs a Go agent connecting to a hardcoded remote broker over WebSocket. The agent spawns a pseudo-terminal and pipes the WebSocket stream into it, granting the remote party interactive shell access. The binary inspects local shell RC files and /etc/hosts, reporting environment details back to the broker. It also supports a second stage where, upon broker approval, it downloads and executes additional npm tarballs with arbitrary code chosen by the attacker. This design allows persistent and flexible remote control of the infected host.
Potential Impact
Successful execution of this package results in full remote shell access to the affected macOS host, enabling arbitrary command execution by the attacker. The attacker can also gather environment information and dynamically deploy further malicious payloads, significantly compromising host confidentiality, integrity, and availability.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should avoid installing or using @ccfly/setup-darwin-x64 version 0.1.7. Remove any installations of this package and audit affected systems for signs of compromise. Monitor for connections to the indicated broker domains and consider network-level blocking of these endpoints. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12313
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735745bf8831d539159eb0
Added to database: 08/05/2026, 15:31:17 UTC
Last enriched: 08/05/2026, 17:22:20 UTC
Last updated: 09/07/2026, 22:23:17 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.