Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

sextant-cli-darwin-arm64npm

sextant-cli-darwin-arm64 is a confirmed malicious npm package (MAL-2026-11997) that steals credentials and exfiltrates sensitive data (malicious versions 0.0.1-rc5, 0.0.1-rc6, 0.0.1-rc7…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in sextant-cli-darwin-arm64 (npm)

MAL-2026-11997
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall sextant-cli-darwin-arm64

What this malware does

Package ships a darwin/arm64 Go binary that opens an outbound WebSocket to a hardcoded author-controlled relay at wss://relay.sextant.top and links a PTY library (github.com/creack/pty) with a WebSocket client (github.com/coder/websocket), implementing the network-driven pseudo-terminal remote-shell pattern that yields full-host code execution to the operator of that relay. The binary additionally binds listeners on 0.0.0.0:7280, 0.0.0.0:7281, and 0.0.0.0:9000 (a 'ws://%s:%s%s' format string is present), exposing the PTY/WebSocket surface to the local network rather than loopback. Embedded strings include a regex specifically matching Anthropic API keys ('sk-ant-[a-z0-9]+-[A-Za-z0-9_-]{40,}') and references to CLAUDE_CONFIG_DIR and ~/.claude paths, allowing extraction of the installer's Anthropic credentials, which are then reachable via the same relay channel. A separate POST to https://relay.sextant.top/install combined with a call to http://ip-api.com/json/?fields=status,message,country,countryCode,city,timezone,query reports installer geolocation and host identity to the author. The npm-facing metadata describes the package only as 'Sextant (sxt) binary for darwin/arm64', while the license field points to a GitHub repository named 'claude_control' — the shipped functionality (remote control of Claude Code / Gemini CLI sessions plus API-key exfiltration) is not disclosed in the package description or README.

Malicious versions

34 flagged
0.0.1-rc50.0.1-rc60.0.1-rc70.0.1-rc80.0.1-rc90.0.1-rc100.0.1-rc110.0.1-rc120.0.1-rc130.0.1-rc140.0.1-rc150.0.1-rc160.0.1-rc170.0.1-rc190.0.1-rc200.0.1-rc210.0.1-rc220.0.1-rc230.0.1-rc240.0.1-rc250.0.1-rc260.0.1-rc270.0.1-rc280.0.1-rc290.0.1-rc300.0.1-rc310.0.1-rc320.0.1-rc330.0.1-rc340.0.1-rc350.0.1-rc360.0.1-rc370.0.1-rc380.0.1-rc39

Indicators of compromise (SHA-256)

395a381c321ebe4cfb276cf354d97d45a8fde8f9882b2d31471a7d6ac5e74229
fe24e808955cc8fd67f5c49e25eb24e793a7638822d4ad9f949df84ec84f3537
7cc2139b9e4cf2fd1d80734e23a313d5c61619b1f59c5507dd8a43f7974fb9eb
a1efc69e5b83ae30eeac5281e41f7d1b47ef27d8554ceea4cd7c4ed2eb327e05
d278b0e3fdda4a2c0d2e31d568f22c433ff5eca932b0c898c157c560c7ed94fe
d558a19027d65b843f291d6a75281072acdd80bbbb7fa0e4b406e35e7232071a
0b9b792dd92c4c7527463c7b8a8b634d042e236b10a228e920d6a45120906d2b
3b0e9f87f2dbf8fab835b00e3a5331455d95e9ce534165edef5a384c297bbd43
5d91d56d74ad284c31e231c17e7ca081186a03f1bfec1340aa13154003155537
20e80ba76f59ca7b25d466ed171d3ef047f5dee1decc0a76441c39094dc6c799
23978b08a7e3f8af97d2c8060e7fc3aca9a18d9f3435163a9d3ab97ac0b9d4d0
bcc8ebc32e36b33b2e18804b02316a4a46b093350f921df3fe9a8fe58fb42de0
cdbbab7489dd57c388d183f453f3aa0d2744e90b9c77beff91229f4e10a13691
02c7c9fa5c471e1b4d08ca15bef1f7b3285e27866497342edefbb42a01d7fe95
0afccffdcebb26b06812f5698aa5b21d9484608e3906b71580bb49ab5c6d163b
c1946cf5905f62b2c8b4ffc3a6046fccc1e852ef2636b4148f6ac6736744ba4b
1da3a3ca217ef4134a6cf2f710574df2916265e418742da8387430b14adcf186
9cbd61c6b3244c1369cf688b99515e4e0efdb2675d27361d622e89d2ba80e460
aa7cfbb5dea81433df5584af6676fff3950e05d87d0f4309c42e258dae35266a
cb8053e951a495b51087f12e7e10dd73bafe49efdc7509057155888d4f30190a
0d24fa0a5bc9680270d1a745260d99e8d70d1da2ee89cd42457bdc90cab48674
157282dcd0238cf5bb765c8207dab98bf9270e09fe6f200d97dec894de70c230
515bea46c6ee2095b2d8ba6d5355926978b5ea010f4e66d04c358070f95b405c
53d7954fe0abd303d9a9034aefa2df24d506cd27bc83a16b20f95c28b24fcffc
73861bb4f7119d8a4cff739f67384c5baa4dd41dca7fbb137b299ca236fa6e24
803c21c3f3f283d59cfa13eb9fdf06042237995e77f0095045f705f93226105c
b49a09c9c3ddcfddb9bcf9a0e6ea158dde495807d76afad99416712856d6075f
a81a5a804a361c18d68d767bda893706722ae036bd3c97d1013d39d1454750d7
75279ebcf38d9a2b62acb5543ee5c5a6243d38d8477b8b1b042808e1e14c2e87
fe9287cf6fe34e95a771fb938c74ba8690e2da0de4e012ec1968c9089807608d
197145c949835b27b6a507c0ef3f59556a786aedc1eb1416a3161db03e200218
a6e1849e1f38f846328f7834b1002f6ea618302c51c4f89927abbf814e012ab4
249a0362cedd0b6f7e7baa94ba3d233a23cb867a14a0389751250c3dc293fd5d
8bbb481c1d433a0f97376b4e6e803a7a618d6e78eae9250a5ffa53137be65d48

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for sextant-cli-darwin-arm64 (34 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging sextant-cli-darwin-arm64 across your stack and pipelines.

  2. If you installed it — respond

    sextant-cli-darwin-arm64 is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If sextant-cli-darwin-arm64 was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks sextant-cli-darwin-arm64 before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. sextant-cli-darwin-arm64 on npm has been identified as a malicious package (versions 0.0.1-rc5, 0.0.1-rc6, 0.0.1-rc7, 0.0.1-rc8, 0.0.1-rc9, 0.0.1-rc10, 0.0.1-rc11, 0.0.1-rc12, and 26 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-011364IN-MAL-2026-014329IN-MAL-2026-014351IN-MAL-2026-014345IN-MAL-2026-014339IN-MAL-2026-014317IN-MAL-2026-014298IN-MAL-2026-014347IN-MAL-2026-014308IN-MAL-2026-014342IN-MAL-2026-014309IN-MAL-2026-014301IN-MAL-2026-014299IN-MAL-2026-014293IN-MAL-2026-014364IN-MAL-2026-014316IN-MAL-2026-014333IN-MAL-2026-014287IN-MAL-2026-014367IN-MAL-2026-014324IN-MAL-2026-014303IN-MAL-2026-014294IN-MAL-2026-014360IN-MAL-2026-014285IN-MAL-2026-014319IN-MAL-2026-014321IN-MAL-2026-014334IN-MAL-2026-014297IN-MAL-2026-014313IN-MAL-2026-014314IN-MAL-2026-015887IN-MAL-2026-016267IN-MAL-2026-017043IN-MAL-2026-017060

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks sextant-cli-darwin-arm64-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

sextant-cli-darwin-arm64 (npm) malicious package — MAL-2026-11997 | O3 Security