目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

sextant-cli-linux-amd64

MAL-2026-12029
2026-08-07 12:53:23
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in sextant-cli-linux-amd64 (npm)

远程访问后门
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
4,407
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
0.0.1-rc12unavailable
0.0.1-rc13unavailable
0.0.1-rc14unavailable
0.0.1-rc15unavailable
0.0.1-rc16unavailable
0.0.1-rc18unavailable
0.0.1-rc19unavailable
0.0.1-rc20unavailable
0.0.1-rc21unavailable
0.0.1-rc24unavailable
0.0.1-rc26unavailable
0.0.1-rc27unavailable
0.0.1-rc28unavailable
0.0.1-rc29unavailable
0.0.1-rc30unavailable
0.0.1-rc32unavailable
0.0.1-rc33unavailable
0.0.1-rc34archivedVIP 下载
0.0.1-rc35unavailable
0.0.1-rc37unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmsextant-cli-linux-amd640.0.1-rc12
npmsextant-cli-linux-amd640.0.1-rc13
npmsextant-cli-linux-amd640.0.1-rc14
npmsextant-cli-linux-amd640.0.1-rc15
npmsextant-cli-linux-amd640.0.1-rc16
npmsextant-cli-linux-amd640.0.1-rc18
npmsextant-cli-linux-amd640.0.1-rc19
npmsextant-cli-linux-amd640.0.1-rc20
npmsextant-cli-linux-amd640.0.1-rc21
npmsextant-cli-linux-amd640.0.1-rc24
npmsextant-cli-linux-amd640.0.1-rc26
npmsextant-cli-linux-amd640.0.1-rc27
npmsextant-cli-linux-amd640.0.1-rc28
npmsextant-cli-linux-amd640.0.1-rc29
npmsextant-cli-linux-amd640.0.1-rc30
npmsextant-cli-linux-amd640.0.1-rc32
npmsextant-cli-linux-amd640.0.1-rc33
npmsextant-cli-linux-amd640.0.1-rc34
npmsextant-cli-linux-amd640.0.1-rc35
npmsextant-cli-linux-amd640.0.1-rc36
npmsextant-cli-linux-amd640.0.1-rc37
npmsextant-cli-linux-amd640.0.1-rc38
npmsextant-cli-linux-amd640.0.1-rc39
npmsextant-cli-linux-amd640.0.1-rc5
npmsextant-cli-linux-amd640.0.1-rc6
npmsextant-cli-linux-amd640.0.1-rc7
npmsextant-cli-linux-amd640.0.1-rc9
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-12029","published":"2026-08-05T00:09:38Z","modified":"2026-08-07T12:53:22.649551717Z","summary":"Malicious code in sextant-cli-linux-amd64 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aab426dad8f1e5722f2836debe2f93730df98b7c109865426208edb687955b30)\nsextant-cli-linux-amd64 ships a Linux amd64 Go binary that, on execution, connects to a hardcoded WebRTC signaling relay at wss://relay.sextant.top and exposes a local interactive shell to a remote controller. The binary uses creack/pty and exec.Command to spawn /bin/bash, /bin/sh, or /bin/zsh under a PTY and forwards stdio through WebRTC data channels, giving a remote party on the sextant.top relay a full interactive shell on the installer's host. The binary also contacts http://ip-api.com/json/ over cleartext HTTP to collect the host's public IP and geolocation and reports it back through the same control channel. Embedded strings referencing /etc/systemd and 'sextantsystemdbootoutdefault.claudekey' indicate a subcommand that installs the agent as a systemd unit for boot persistence. package.json's license URL points to https://github.com/ddos798/claude_control, and the binary internally references 'claude_control' and api.anthropic.com, consistent with a tool designed to remotely pilot the installer's host and Claude Code sessions. Regardless of the tool's advertised purpose, a network-sourced controller driving a PTY on the installer's machine, with systemd persistence support and host reconnaissance to a third-party geolocation service, constitutes a persistent remote backdoor into the installer host.\n","affected":[{"package":{"name":"sextant-cli-linux-amd64","ecosystem":"npm"},"versions":["0.0.1-rc34","0.0.1-rc26","0.0.1-rc32","0.0.1-rc13","0.0.1-rc18","0.0.1-rc28","0.0.1-rc21","0.0.1-rc5","0.0.1-rc30","0.0.1-rc35","0.0.1-rc7","0.0.1-rc9","0.0.1-rc20","0.0.1-rc24","0.0.1-rc29","0.0.1-rc15","0.0.1-rc27","0.0.1-rc19","0.0.1-rc14","0.0.1-rc33","0.0.1-rc12","0.0.1-rc6","0.0.1-rc16","0.0.1-rc37","0.0.1-rc36","0.0.1-rc38","0.0.1-rc39"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"bin/sxt","sha256":"65f5217f1613bbbbe76ca5d1258d06654d6f85462da50ff6f9cac4434dc4e021","tlsh":"3cd63807eca645e8c5aec130cab696237b717c494b3023e31b54b6397f76bd06ab9710"},{"path":"package.json","sha256":"7e71ed096f336af61178da974b6796d82def7979cb95e145f62ec425544167b5","tlsh":"c3d0a751843401735eec5fd41e21d00d66308da594067859ff7b2548022d67369ba6ac"}],"package_integrity":[{"filename":"sextant-cli-linux-amd64-0.0.1-rc34.tgz","hashes":{"sha1":"cc99627252d1ed93dbe646fdfaaa4af818e90c46","sha512_sri":"sha512-31aFwv8WdnbGSJb7QC5JbTtXyGoJgWxAFkjVinm87RGGx1LvhNE6yBqyjzPSO41zWMbNfIVE/a27HLkf6+frkw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc34"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc26"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc32"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc13"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc18"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc28"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc21"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc30"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc35"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc20"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc24"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc29"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc15"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc27"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc19"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc14"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc33"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc12"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc16"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc37"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc36"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc38"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sextant-cli-linux-amd64/v/0.0.1-rc39"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-011397","import_time":"2026-08-05T00:44:43.315412896Z","modified_time":"2026-08-05T00:09:38Z","sha256":"56cebc1e798691d2dca22f19177333a2e8dba9e4e53c11f9d76de42a1a1c67cf","source":"amazon-inspector","versions":["0.0.1-rc34"]},{"id":"IN-MAL-2026-011496","import_time":"2026-08-05T01:39:31.594436982Z","modified_time":"2026-08-05T01:23:25Z","sha256":"050c3a85c61d8fda2bf3555179d2049da12e6b7624d2d499093afdbc179b5a96","source":"amazon-inspector","versions":["0.0.1-rc26"]},{"id":"IN-MAL-2026-011511","import_time":"2026-08-05T03:11:15.807717475Z","modified_time":"2026-08-05T01:41:12Z","sha256":"546e48fd8a2f238b4f5705420c8b74f2af2f7e8b67b9cd9f01159a01d6bd414f","source":"amazon-inspector","versions":["0.0.1-rc32"]},{"id":"IN-MAL-2026-014379","import_time":"2026-08-05T09:28:04.317305919Z","modified_time":"2026-08-05T08:41:56Z","sha256":"628ee990b20330de3a2b94bca68929113f4a77963ab0893209511616dce27b8e","source":"amazon-inspector","versions":["0.0.1-rc13"]},{"id":"IN-MAL-2026-014378","import_time":"2026-08-05T09:28:04.190656765Z","modified_time":"2026-08-05T08:41:49Z","sha256":"a2fa744ca1da8940b6de39da5a0fb0222e55772ff2ceb131ef5c7cf65904fd10","source":"amazon-inspector","versions":["0.0.1-rc18"]},{"id":"IN-MAL-2026-014330","import_time":"2026-08-05T09:27:57.676190676Z","modified_time":"2026-08-05T08:35:02Z","sha256":"fdcb5b0d8d09d850fd57fb398de7fde24ecd0d982bdda498dc07ae684b6aefc6","source":"amazon-inspector","versions":["0.0.1-rc28"]},{"id":"IN-MAL-2026-014375","import_time":"2026-08-05T09:28:03.750912985Z","modified_time":"2026-08-05T08:41:22Z","sha256":"3234d5a1055f4a2d4f835c186fe69f973446beafb673a5e56050cbbcd67a3b11","source":"amazon-inspector","versions":["0.0.1-rc21"]},{"id":"IN-MAL-2026-014381","import_time":"2026-08-05T09:28:04.509124749Z","modified_time":"2026-08-05T08:42:12Z","sha256":"362444e113c470f5fb6efc1af9ef59a3ff1e8bdcfc9b569c6b06b1bfbf7cde2e","source":"amazon-inspector","versions":["0.0.1-rc5"]},{"id":"IN-MAL-2026-014372","import_time":"2026-08-05T09:28:03.424910259Z","modified_time":"2026-08-05T08:40:57Z","sha256":"b3d2ee4b5d82fc8a673206903bca6c72be413511ec968ac74b3902aaca5c3637","source":"amazon-inspector","versions":["0.0.1-rc30"]},{"id":"IN-MAL-2026-014385","import_time":"2026-08-05T09:28:04.929497221Z","modified_time":"2026-08-05T08:42:43Z","sha256":"e77a04e5d2060d173bc9b6b87efbc760daa5ba07ff55b9f2346258890effa8cd","source":"amazon-inspector","versions":["0.0.1-rc35"]},{"id":"IN-MAL-2026-014361","import_time":"2026-08-05T09:28:02.177835925Z","modified_time":"2026-08-05T08:39:24Z","sha256":"3411ae498b9f0953fd9211a1e775a488f7fad1b3a33e7cdcef2720a24a6784e5","source":"amazon-inspector","versions":["0.0.1-rc7"]},{"id":"IN-MAL-2026-014295","import_time":"2026-08-05T09:27:53.098882114Z","modified_time":"2026-08-05T08:29:47Z","sha256":"93cdee3a41d3e26b2453278b34a41dadef9bf05b4680c0f9f1f062836c3b0227","source":"amazon-inspector","versions":["0.0.1-rc9"]},{"id":"IN-MAL-2026-014344","import_time":"2026-08-05T09:27:59.423026204Z","modified_time":"2026-08-05T08:37:01Z","sha256":"aa2c4f89953674713c128cbdaf55e061a95315de5e03c22b1bfbf1af87f8e9d8","source":"amazon-inspector","versions":["0.0.1-rc20"]},{"id":"IN-MAL-2026-014373","import_time":"2026-08-05T09:28:03.549131373Z","modified_time":"2026-08-05T08:41:04Z","sha256":"aef6e14c7cb82a5f0deb90014957ec05caaa6da04b2a6a7824d3149b2aa361bf","source":"amazon-inspector","versions":["0.0.1-rc24"]},{"id":"IN-MAL-2026-014288","import_time":"2026-08-05T09:27:52.213382486Z","modified_time":"2026-08-05T08:28:42Z","sha256":"ef2c5b4e1a7b46248be73f0ae010359845d3f51ea19241e17625021d91c2ec9c","source":"amazon-inspector","versions":["0.0.1-rc29"]},{"id":"IN-MAL-2026-014349","import_time":"2026-08-05T09:27:59.949900976Z","modified_time":"2026-08-05T08:37:47Z","sha256":"50ddc84aa24e2b41df216961ed92a6953b136d72461acbb2a114316849a3fe67","source":"amazon-inspector","versions":["0.0.1-rc15"]},{"id":"IN-MAL-2026-014335","import_time":"2026-08-05T09:27:58.395365522Z","modified_time":"2026-08-05T08:35:46Z","sha256":"5836ffb718d0e4972f488124097994e72764198184dd0690e21ad0e3eefa1797","source":"amazon-inspector","versions":["0.0.1-rc27"]},{"id":"IN-MAL-2026-014377","import_time":"2026-08-05T09:28:04.090225876Z","modified_time":"2026-08-05T08:41:39Z","sha256":"6b4a47d82e4ae6ba6e691f3e0bf9b8c7e309181cabf97da885502f4f0835e959","source":"amazon-inspector","versions":["0.0.1-rc19"]},{"id":"IN-MAL-2026-014386","import_time":"2026-08-05T09:28:05.063946063Z","modified_time":"2026-08-05T08:42:52Z","sha256":"96d8245de87819d034af12650855d5df22d028b54c54408450ad6a9f1a07f87e","source":"amazon-inspector","versions":["0.0.1-rc14"]},{"id":"IN-MAL-2026-014327","import_time":"2026-08-05T09:27:57.204910481Z","modified_time":"2026-08-05T08:34:31Z","sha256":"e288e053e8f8f6391eed39abd1e967c1a4a382fb4976574c962dc085d9881561","source":"amazon-inspector","versions":["0.0.1-rc33"]},{"id":"IN-MAL-2026-014355","import_time":"2026-08-05T09:28:01.103063926Z","modified_time":"2026-08-05T08:38:36Z","sha256":"1175f4e0cdb7410fb13946451e1ff09da6057e056243d9606718a14ad39444fb","source":"amazon-inspector","versions":["0.0.1-rc12"]},{"id":"IN-MAL-2026-014363","import_time":"2026-08-05T09:28:02.350629028Z","modified_time":"2026-08-05T08:39:42Z","sha256":"3d28705c73cb1063bf806be02f901aa1b6a82b1a637eb8cf192f2fa97cf32840","source":"amazon-inspector","versions":["0.0.1-rc6"]},{"id":"IN-MAL-2026-014350","import_time":"2026-08-05T09:28:00.038664712Z","modified_time":"2026-08-05T08:37:56Z","sha256":"4377c05245a4ddc82253aee80765ce2beb99fec159ee18b22713c1c12ac5e44a","source":"amazon-inspector","versions":["0.0.1-rc16"]},{"id":"IN-MAL-2026-015886","import_time":"2026-08-05T20:07:26.517902019Z","modified_time":"2026-08-05T19:49:57Z","sha256":"ff3296d588369230cf8184e621ef092ec0446a1c7bcda31a527bda5a6719fd6f","source":"amazon-inspector","versions":["0.0.1-rc37"]},{"id":"IN-MAL-2026-016268","import_time":"2026-08-06T13:09:08.720547848Z","modified_time":"2026-08-06T12:56:15Z","sha256":"aab426dad8f1e5722f2836debe2f93730df98b7c109865426208edb687955b30","source":"amazon-inspector","versions":["0.0.1-rc36"]},{"id":"IN-MAL-2026-017059","import_time":"2026-08-07T12:51:24.362372096Z","modified_time":"2026-08-07T12:37:57Z","sha256":"0cd87a2113c2322b64dc2e52d2b279fd0bfb8481d0dba596ac202e638e188bae","source":"amazon-inspector","versions":["0.0.1-rc38"]},{"id":"IN-MAL-2026-017056","import_time":"2026-08-07T12:51:24.249237173Z","modified_time":"2026-08-07T12:37:30Z","sha256":"96b4c6da5028d62823603e9f94fd2c630f6adf93304631702a794a75be4ddb32","source":"amazon-inspector","versions":["0.0.1-rc39"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0