Malicious code in sextant-cli-linux-arm64 (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (fc34f69b5a68c549feccfb32cc2dbfbf2d4c787a4876241027b4299305fd2c53) The package is a platform-specific leaf (linux/arm64) whose only shipped artifact is a 12 MB stripped Go binary at bin/sxt. The package.json omits repository, author, main, bin, files, and scripts fields, and its license field points at github.com/ddos798/claude_control — a self-labeled 'claude_control' project. Strings in bin/sxt reveal a full WebRTC stack (pion/webrtc/v4, pion/turn/v5, pion/ice/v4, coder/websocket, go-qrcode) plus a hardcoded signaling/relay endpoint https://relay.sextant.top/install, giving the binary the shape of a remote-control agent that pairs the installer's host to an author-controlled peer over WebRTC data channels. Adjacent strings 'sk-ant-', 'CLAUDE_CONFIG_DIR', 'https://api.anthropic.com/v1/models', 'https://claude.ai/install.sh', and '@google/gemini-cli' show the binary is positioned to read Anthropic API keys and Claude Code / Gemini CLI configuration from the installer and hand them to the remote peer through the established channel. An additional string http://ip-api.com/json/ provides public-IP geolocation of the host for the remote operator. The combination of an opaque metadata-only npm manifest, a bundled native binary embedding a full peer-to-peer control stack, a hardcoded author relay, and embedded references to developer AI-credential material is a backdoor with credential-theft capability against the installer.
AI Analysis
Technical Summary
The sextant-cli-linux-arm64 package is a platform-specific npm package for Linux ARM64 that ships a single 12 MB stripped Go binary named bin/sxt. This binary embeds a full WebRTC peer-to-peer communication stack and connects to a hardcoded signaling/relay endpoint (https://relay.sextant.top/install) controlled by the attacker. The binary is capable of remotely controlling the infected host and exfiltrating sensitive AI developer credentials, including Anthropic API keys and Claude/Gemini CLI configurations, by reading local configuration files and sending them over the established WebRTC channel. It also collects public IP geolocation data via http://ip-api.com/json/. The package.json manifest is minimal and lacks typical metadata fields such as repository, author, main, bin, files, and scripts, and its license field points to a suspicious project. This combination of factors indicates a deliberate backdoor with credential theft capabilities embedded in the npm package.
Potential Impact
The malicious binary enables remote attackers to gain persistent control over the infected host via a peer-to-peer WebRTC channel. It can exfiltrate sensitive AI-related credentials and configuration files, potentially compromising the security and privacy of AI development environments. The collection of public IP geolocation data further aids attacker situational awareness. This can lead to unauthorized access to AI service accounts and potential misuse of those credentials. No known exploits in the wild have been reported yet.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing or using any versions of sextant-cli-linux-arm64 listed as affected. Remove any existing installations of this package and audit systems for the presence of the bin/sxt binary. Monitor for suspicious network connections to the hardcoded relay endpoint (https://relay.sextant.top/install). Consider using trusted sources and verifying package integrity before installation. Check vendor advisories or npm security notices for updates or removal of the malicious package.
Malicious code in sextant-cli-linux-arm64 (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (fc34f69b5a68c549feccfb32cc2dbfbf2d4c787a4876241027b4299305fd2c53) The package is a platform-specific leaf (linux/arm64) whose only shipped artifact is a 12 MB stripped Go binary at bin/sxt. The package.json omits repository, author, main, bin, files, and scripts fields, and its license field points at github.com/ddos798/claude_control — a self-labeled 'claude_control' project. Strings in bin/sxt reveal a full WebRTC stack (pion/webrtc/v4, pion/turn/v5, pion/ice/v4, coder/websocket, go-qrcode) plus a hardcoded signaling/relay endpoint https://relay.sextant.top/install, giving the binary the shape of a remote-control agent that pairs the installer's host to an author-controlled peer over WebRTC data channels. Adjacent strings 'sk-ant-', 'CLAUDE_CONFIG_DIR', 'https://api.anthropic.com/v1/models', 'https://claude.ai/install.sh', and '@google/gemini-cli' show the binary is positioned to read Anthropic API keys and Claude Code / Gemini CLI configuration from the installer and hand them to the remote peer through the established channel. An additional string http://ip-api.com/json/ provides public-IP geolocation of the host for the remote operator. The combination of an opaque metadata-only npm manifest, a bundled native binary embedding a full peer-to-peer control stack, a hardcoded author relay, and embedded references to developer AI-credential material is a backdoor with credential-theft capability against the installer.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sextant-cli-linux-arm64 package is a platform-specific npm package for Linux ARM64 that ships a single 12 MB stripped Go binary named bin/sxt. This binary embeds a full WebRTC peer-to-peer communication stack and connects to a hardcoded signaling/relay endpoint (https://relay.sextant.top/install) controlled by the attacker. The binary is capable of remotely controlling the infected host and exfiltrating sensitive AI developer credentials, including Anthropic API keys and Claude/Gemini CLI configurations, by reading local configuration files and sending them over the established WebRTC channel. It also collects public IP geolocation data via http://ip-api.com/json/. The package.json manifest is minimal and lacks typical metadata fields such as repository, author, main, bin, files, and scripts, and its license field points to a suspicious project. This combination of factors indicates a deliberate backdoor with credential theft capabilities embedded in the npm package.
Potential Impact
The malicious binary enables remote attackers to gain persistent control over the infected host via a peer-to-peer WebRTC channel. It can exfiltrate sensitive AI-related credentials and configuration files, potentially compromising the security and privacy of AI development environments. The collection of public IP geolocation data further aids attacker situational awareness. This can lead to unauthorized access to AI service accounts and potential misuse of those credentials. No known exploits in the wild have been reported yet.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing or using any versions of sextant-cli-linux-arm64 listed as affected. Remove any existing installations of this package and audit systems for the presence of the bin/sxt binary. Monitor for suspicious network connections to the hardcoded relay endpoint (https://relay.sextant.top/install). Consider using trusted sources and verifying package integrity before installation. Check vendor advisories or npm security notices for updates or removal of the malicious package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12043
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a73851ebf8831d5394ef789
Added to database: 08/05/2026, 18:46:54 UTC
Last enriched: 08/05/2026, 23:18:26 UTC
Last updated: 09/07/2026, 22:04:04 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.