Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

sextant-cli-darwin-amd64npm

sextant-cli-darwin-amd64 is a confirmed malicious npm package (MAL-2026-12028) that steals credentials and exfiltrates sensitive data (malicious versions 0.0.1-rc5, 0.0.1-rc6, 0.0.1-rc7…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in sextant-cli-darwin-amd64 (npm)

MAL-2026-12028
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall sextant-cli-darwin-amd64

What this malware does

The tarball contains a single 13.4 MB Mach-O darwin/amd64 Go binary at bin/sxt and a package.json with no source, no main, no bin mapping, and no scripts — the package is a platform-artifact shipped for consumption as an optionalDependency by a parent sextant-cli. Strings extracted from bin/sxt show it embeds github.com/coder/websocket and github.com/creack/pty together with the hardcoded relay URL wss://relay.sextant.top; that network-to-PTY dataflow is a remote-shell backdoor driven by an attacker-controlled WebSocket relay on the installer's host. The same binary contains the Anthropic API-key regex sk-ant-[a-z0-9]+-[A-Za-z0-9_-]{40,} alongside CLAUDE_CONFIG_DIR=, https://claude.ai/, and https://api.anthropic.com/v1/models, indicating the binary reads the installer's Claude configuration directory and fingerprints sk-ant-* credentials for exfiltration through the same relay. Additional strings embed http://ip-api.com/json/?fields=status,message,country,countryCode,city,timezone,isp,org,as,proxy,hosting,mobile,query, profiling the installer's public IP, city, ISP, org, ASN, and hosting/proxy flags. package.json declares its license as SEE LICENSE IN https://github.com/ddos798/claude_control, and the binary references https://claude.ai/install.sh and https://registry.npmjs.org/sextant-cli/latest for self-update. Delivering behavior only as a stripped compiled binary conceals the network-to-PTY, credential-regex, and geolocation logic from JS-level inspection.

Malicious versions

35 flagged
0.0.1-rc50.0.1-rc60.0.1-rc70.0.1-rc80.0.1-rc90.0.1-rc100.0.1-rc110.0.1-rc120.0.1-rc130.0.1-rc140.0.1-rc150.0.1-rc160.0.1-rc170.0.1-rc180.0.1-rc190.0.1-rc200.0.1-rc210.0.1-rc220.0.1-rc230.0.1-rc240.0.1-rc250.0.1-rc260.0.1-rc270.0.1-rc280.0.1-rc290.0.1-rc300.0.1-rc310.0.1-rc320.0.1-rc330.0.1-rc340.0.1-rc350.0.1-rc360.0.1-rc370.0.1-rc380.0.1-rc39

Indicators of compromise (SHA-256)

4da71f2071285bfe8543d8aa7437f2b82111d95797f78ece2cf7498d02ff9cc1
8ec015aabfc62dff864495c55a843f27de7ad643be1cd16c847542d2b492276f
beb6fac9ef14e4420488f91db4a3611492970a0391a7ed525f2093e1639cd0d4
cea82d3f63d4bfc12706277fb9b372fb921233bc8e6e7da0df30d2fec4143d45
176744255653f7306997ec4017221942d5262fe934ef6972e55e93ca46fe4272
3c0a77e02596335bf566a31445467cab1dce963b7e753fbc067cc330c82a37cc
b69236fcb44cf363593c779d36704726a28c68d0bf15fc986810575c285c6387
643e2c52a14d58d361874e0746d53c7fba136fc7dd8655bea0e6b12b3f6cc32c
062689c7eb753d43d7319f042585d39b929e14cf0d609da842bc0f35499aab06
7487ed84a2ee2c397adc615962e85086a371e6108378b5298179d73805cb8353
d0a4579ae1dd2ccffaf28302af4e1565775241f9b1d0c5e861df2c8554227c57
e0a1ca6f4e48ee3ee376c62bf04d229eef9b9c28c4d5704aeb01efbf4b963f94
0dbc296faa091033a145f485d51789ead79b91716bb0ddbbbbaec38bcfe990c4
08ab037c781a77b323dc720da773cdbd283b8104a6ceaba93eab09b2dde7644b
52ab46f4de0ab24a68d3cd1db4e6b752e39db8a870a4df1ace5575fdd2400e0f
7c2ffb43db99172500191d797e6c3d6e189dc78b9d5f1973411031d36507d159
9d2e5ab6503eb2b9c12bf64e34cb2fe12227c07b179231ebe23f13b8866181f1
e17a84407d1c8b91240f6eb38704bcf11e7bed3b3ed38c90ac727f5526b7b2d0
ef741ddc2626420bbf83f3b8d99f2c1f22f347e438bb959021dfea8f9d03a3c6
fd14e772b597978bb7f59bf8f2a70d91655099210af716036b9d596a0a99a6c0
38084d2ddef3a61c81d025e654545d07bbba773fb89e04cdadfdd9d82c922011
67e09f48d2a485c796f3872b327e86a5523ee69bb4289fe9e3033f0f3cd43ecf
b703b004ecba01397c378b3e56d9f22d7f4e822c14d3ce58e40513730000952f
4a08fb404b42923ca00d403a2e93d904ed6694ce245a0bb81fc58a21757bfb4b
6d19f5aab58eb6b8a605b2133a9074e474ea395bb78cff25fba0cf57374eba39
8110d0d64570cbfdd0e1b6da8166e5b3e01060908766f038338af489ecaae71d
955711067836acd1442fa265aff200afe40023a7e65f210298bdb87ef8fe1942
b3efc75b637a6953d87fb80a3308ec47fb0a27985c9dc22af68ef082feae9080
c719c58e060f4978dbf3384521ba75e955ee49796c73ef1a26aef224b5c5c565
3e363ee49349bb2fa8d05d057995bb419385be364e1899c71fe51be8f23027b5
77e89f39191222fe553f7ae17512bb9b97566702de7c26c50538a4605e9135f3
d9e92f0e4d8bf5d9f5237d632b2c9c106705654fa0d463796a8e5b0accade86f
084aa59226b6f1c91e205d09ed3af1076691f739a14ff70485e6459ab295c9dd
90397ffd4e0dac7ae0725feb608c5f7800510d886567abcbf714b47483baa0de
0339098220f110c278095abb49998ef402f2563fbaaa8facfd76c944367475e4

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for sextant-cli-darwin-amd64 (35 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging sextant-cli-darwin-amd64 across your stack and pipelines.

  2. If you installed it — respond

    sextant-cli-darwin-amd64 is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If sextant-cli-darwin-amd64 was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks sextant-cli-darwin-amd64 before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. sextant-cli-darwin-amd64 on npm has been identified as a malicious package (versions 0.0.1-rc5, 0.0.1-rc6, 0.0.1-rc7, 0.0.1-rc8, 0.0.1-rc9, 0.0.1-rc10, 0.0.1-rc11, 0.0.1-rc12, and 27 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-011398IN-MAL-2026-014305IN-MAL-2026-014357IN-MAL-2026-014290IN-MAL-2026-014322IN-MAL-2026-014356IN-MAL-2026-014300IN-MAL-2026-014366IN-MAL-2026-014291IN-MAL-2026-014341IN-MAL-2026-014311IN-MAL-2026-014320IN-MAL-2026-014306IN-MAL-2026-014296IN-MAL-2026-014292IN-MAL-2026-014289IN-MAL-2026-014332IN-MAL-2026-014304IN-MAL-2026-014336IN-MAL-2026-014312IN-MAL-2026-014331IN-MAL-2026-014362IN-MAL-2026-014302IN-MAL-2026-014318IN-MAL-2026-014307IN-MAL-2026-014315IN-MAL-2026-014286IN-MAL-2026-014323IN-MAL-2026-014284IN-MAL-2026-014369IN-MAL-2026-014310IN-MAL-2026-014644IN-MAL-2026-015885IN-MAL-2026-017041IN-MAL-2026-017040

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks sextant-cli-darwin-amd64-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

sextant-cli-darwin-amd64 (npm) malicious package — MAL-2026-12028 | O3 Security