VYPR

npm · Malicious package advisory

Malware

@ccfly/setup-darwin-arm64

MAL-2026-12084

Malicious code in @ccfly/setup-darwin-arm64 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9fe0ce193f188d4dea838316c4bd1ee211342a177038c2c8cd3dbfaa65d8c016)
The tarball's sole payload is a macOS/arm64 Go executable (under bin/) that opens a WebSocket connection to a hardcoded remote server (strings include ws://ccfly and wss:// endpoints plus a /rescue/status?session=...&agent=... path) and pipes received messages into a PTY-attached local shell built from github.com/creack/pty, github.com/gorilla/websocket, and os/exec. Chinese-language pairing/approval prompts embedded in the binary describe enrolling the host so that it can be remotely controlled from a web or phone client to drive 'Claude Code'; the binary also writes to ~/.zshrc and ~/.bash_profile for shell persistence and references anthropic.com / ANTHROPIC_CUSTOM_HEADERS. package.json declares no scripts, main, or bin, so installing this platform-specific sub-package alone does not auto-execute code; it acts as the carrier that places the agent on disk for a parent @ccfly/setup CLI to launch. Once the agent runs and a remote party completes pairing, that party obtains an interactive shell on the installer's macOS host, which is a remote-access backdoor regardless of the advertised remote-control-for-Claude-Code framing.

Compromised versions (1)

  • 0.1.20

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.