Malicious code in sextant-cli-darwin-amd64 (npm)
The sextant-cli-darwin-amd64 npm package contains a malicious Mach-O binary that acts as a remote shell backdoor. It connects to an attacker-controlled WebSocket relay to enable remote command execution. The binary also searches for Anthropic Claude API keys in the installer's configuration and exfiltrates them through the same relay. Additionally, it collects geolocation and ISP information about the host machine. The malicious behavior is concealed within a compiled binary, preventing detection through typical JavaScript inspection. Multiple release candidate versions of sextant-cli-darwin-amd64 are affected.
AI Analysis
Technical Summary
The sextant-cli-darwin-amd64 package includes a 13.4 MB Mach-O Go binary that implements a remote shell backdoor by relaying network data to a pseudo-terminal via a WebSocket connection to wss://relay.sextant.top. The binary embeds libraries for WebSocket and PTY handling and contains logic to locate and exfiltrate Anthropic Claude API keys (matching the regex sk-ant-[a-z0-9]+-[A-Za-z0-9_-]{40,}) from the installer's Claude configuration directory. It also queries an IP geolocation service (http://ip-api.com) to profile the host's public IP, city, ISP, ASN, and proxy/hosting status. The package.json lacks source code or scripts, indicating the binary is the sole payload. The binary references URLs for self-update and license information, further indicating malicious intent. This behavior is hidden from JavaScript-level inspection due to the binary-only delivery.
Potential Impact
This malicious package enables attackers to gain remote shell access on affected hosts, allowing arbitrary command execution. It also steals sensitive Anthropic Claude API credentials from the user's environment, potentially compromising access to AI services. The collection of geolocation and ISP data facilitates profiling of victims. The backdoor and credential theft pose significant confidentiality and integrity risks to affected systems and user data.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately uninstall all affected versions of sextant-cli-darwin-amd64 (listed below) and avoid installing this package. Since the malicious behavior is embedded in a compiled binary, standard JavaScript code reviews will not detect it. Monitor for network connections to wss://relay.sextant.top and related suspicious activity. Check for presence of the binary 'bin/sxt' in the package installation directory and remove if found. Consider rotating any exposed Anthropic Claude API keys. Stay updated with vendor or npm advisories for any future fixes or guidance.
Malicious code in sextant-cli-darwin-amd64 (npm)
Description
The sextant-cli-darwin-amd64 npm package contains a malicious Mach-O binary that acts as a remote shell backdoor. It connects to an attacker-controlled WebSocket relay to enable remote command execution. The binary also searches for Anthropic Claude API keys in the installer's configuration and exfiltrates them through the same relay. Additionally, it collects geolocation and ISP information about the host machine. The malicious behavior is concealed within a compiled binary, preventing detection through typical JavaScript inspection. Multiple release candidate versions of sextant-cli-darwin-amd64 are affected.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sextant-cli-darwin-amd64 package includes a 13.4 MB Mach-O Go binary that implements a remote shell backdoor by relaying network data to a pseudo-terminal via a WebSocket connection to wss://relay.sextant.top. The binary embeds libraries for WebSocket and PTY handling and contains logic to locate and exfiltrate Anthropic Claude API keys (matching the regex sk-ant-[a-z0-9]+-[A-Za-z0-9_-]{40,}) from the installer's Claude configuration directory. It also queries an IP geolocation service (http://ip-api.com) to profile the host's public IP, city, ISP, ASN, and proxy/hosting status. The package.json lacks source code or scripts, indicating the binary is the sole payload. The binary references URLs for self-update and license information, further indicating malicious intent. This behavior is hidden from JavaScript-level inspection due to the binary-only delivery.
Potential Impact
This malicious package enables attackers to gain remote shell access on affected hosts, allowing arbitrary command execution. It also steals sensitive Anthropic Claude API credentials from the user's environment, potentially compromising access to AI services. The collection of geolocation and ISP data facilitates profiling of victims. The backdoor and credential theft pose significant confidentiality and integrity risks to affected systems and user data.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately uninstall all affected versions of sextant-cli-darwin-amd64 (listed below) and avoid installing this package. Since the malicious behavior is embedded in a compiled binary, standard JavaScript code reviews will not detect it. Monitor for network connections to wss://relay.sextant.top and related suspicious activity. Check for presence of the binary 'bin/sxt' in the package installation directory and remove if found. Consider rotating any exposed Anthropic Claude API keys. Stay updated with vendor or npm advisories for any future fixes or guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12028
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735741bf8831d539155f4d
Added to database: 08/05/2026, 15:31:13 UTC
Last enriched: 08/05/2026, 17:02:22 UTC
Last updated: 08/05/2026, 17:02:22 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.