Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in sextant-cli-darwin-amd64 (npm)

0
Critical
Published: 08/05/2026 (08/05/2026, 00:09:51 UTC)
Source: GCVE Database
Product: sextant-cli-darwin-amd64

Description

The sextant-cli-darwin-amd64 npm package contains a malicious Mach-O binary that acts as a remote shell backdoor. It connects to an attacker-controlled WebSocket relay to enable remote command execution. The binary also searches for Anthropic Claude API keys in the installer's configuration and exfiltrates them through the same relay. Additionally, it collects geolocation and ISP information about the host machine. The malicious behavior is concealed within a compiled binary, preventing detection through typical JavaScript inspection. Multiple release candidate versions of sextant-cli-darwin-amd64 are affected.

Affected software

npmghsa
sextant-cli-darwin-amd64
Affected versions
=0.0.1-rc34=0.0.1-rc31=0.0.1-rc10=0.0.1-rc16=0.0.1-rc11=0.0.1-rc12=0.0.1-rc26=0.0.1-rc6=0.0.1-rc24=0.0.1-rc22=0.0.1-rc14=0.0.1-rc23=0.0.1-rc19=0.0.1-rc35=0.0.1-rc18=0.0.1-rc20=0.0.1-rc27=0.0.1-rc21=0.0.1-rc25=0.0.1-rc13=0.0.1-rc28=0.0.1-rc7=0.0.1-rc29=0.0.1-rc30=0.0.1-rc17=0.0.1-rc8=0.0.1-rc33=0.0.1-rc9=0.0.1-rc32=0.0.1-rc5=0.0.1-rc15=0.0.1-rc36

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:02:22 UTC

Technical Analysis

The sextant-cli-darwin-amd64 package includes a 13.4 MB Mach-O Go binary that implements a remote shell backdoor by relaying network data to a pseudo-terminal via a WebSocket connection to wss://relay.sextant.top. The binary embeds libraries for WebSocket and PTY handling and contains logic to locate and exfiltrate Anthropic Claude API keys (matching the regex sk-ant-[a-z0-9]+-[A-Za-z0-9_-]{40,}) from the installer's Claude configuration directory. It also queries an IP geolocation service (http://ip-api.com) to profile the host's public IP, city, ISP, ASN, and proxy/hosting status. The package.json lacks source code or scripts, indicating the binary is the sole payload. The binary references URLs for self-update and license information, further indicating malicious intent. This behavior is hidden from JavaScript-level inspection due to the binary-only delivery.

Potential Impact

This malicious package enables attackers to gain remote shell access on affected hosts, allowing arbitrary command execution. It also steals sensitive Anthropic Claude API credentials from the user's environment, potentially compromising access to AI services. The collection of geolocation and ISP data facilitates profiling of victims. The backdoor and credential theft pose significant confidentiality and integrity risks to affected systems and user data.

Mitigation Recommendations

No official patch or remediation is currently available. Users should immediately uninstall all affected versions of sextant-cli-darwin-amd64 (listed below) and avoid installing this package. Since the malicious behavior is embedded in a compiled binary, standard JavaScript code reviews will not detect it. Monitor for network connections to wss://relay.sextant.top and related suspicious activity. Check for presence of the binary 'bin/sxt' in the package installation directory and remove if found. Consider rotating any exposed Anthropic Claude API keys. Stay updated with vendor or npm advisories for any future fixes or guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12028
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a735741bf8831d539155f4d

Added to database: 08/05/2026, 15:31:13 UTC

Last enriched: 08/05/2026, 17:02:22 UTC

Last updated: 08/05/2026, 17:02:22 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses