MAL-2026-12084

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@ccfly/setup-darwin-arm64/MAL-2026-12084.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12084
Published
2026-08-05T06:21:11Z
Modified
2026-08-06T14:34:45.390930813Z
Summary
Malicious code in @ccfly/setup-darwin-arm64 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4d5a88a77e76664c9050d9bad333214c053469264fff83ba56e2a68eaecfdfaa)

The tarball ships a single 6.4 MB Go binary at bin/ccfly-setup for darwin/arm64. The binary links github.com/gorilla/websocket and github.com/creack/pty and contains hardcoded strings 'wss://', 'ws://ccfly', and host 'cc.hn' alongside os/exec.Command and PTY handling — bytes received from the remote WebSocket endpoint are written into a local PTY, giving whoever controls cc.hn command execution on the host running the binary. Additional binary strings ('anthropic.com', 'claude.ai', '127.0.0.1:443', '.zshrc', '.bashprofile', 'export', 'approveccfly-*/redeem', 'https://cc.hn') show the binary also stands up a local 127.0.0.1:443 listener and writes export lines into ~/.zshrc and ~/.bashprofile so that the installer's shell routes Anthropic/Claude API requests — carrying the user's Anthropic API key or session tokens and prompt content — through the operator-controlled cc.hn infrastructure. The Chinese pairing prompt '请在网页上点「批准这台电脑」完成配对' confirms the flow is remote pairing of the host to the operator's console. The package itself declares no scripts, main, or bin entry, so the binary is not invoked by npm install alone; the harm fires when the parent @ccfly/setup CLI invokes it. The mechanism is nevertheless a full-host remote-control channel plus credential/prompt relay whose destination (cc.hn) is hardcoded and not caller-configured.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T06:21:11Z",
            "sha256": "9fe0ce193f188d4dea838316c4bd1ee211342a177038c2c8cd3dbfaa65d8c016",
            "id": "IN-MAL-2026-013424",
            "versions": [
                "0.1.20"
            ],
            "import_time": "2026-08-05T07:06:46.958823508Z"
        },
        {
            "import_time": "2026-08-06T14:19:52.965515038Z",
            "sha256": "6e84698e75d86fc8e9ff5a65d421a2fb3e1cef8bc2ed89791dbd1c09bbf59543",
            "modified_time": "2026-08-06T13:49:40Z",
            "id": "IN-MAL-2026-016510",
            "versions": [
                "0.1.5"
            ],
            "source": "amazon-inspector"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T13:49:08Z",
            "sha256": "6eb9ed7b0a33e59ac1eed95dba9df4fac3997b704db0dab0756473a0c6fdba53",
            "id": "IN-MAL-2026-016506",
            "versions": [
                "0.1.10"
            ],
            "import_time": "2026-08-06T14:19:52.811844136Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T13:50:00Z",
            "sha256": "805d6bdac4be04d616e028b1b1ece9e56b79906d558fbdbef79a1e0303f77cca",
            "id": "IN-MAL-2026-016512",
            "versions": [
                "0.1.14"
            ],
            "import_time": "2026-08-06T14:19:53.081757376Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T13:49:24Z",
            "sha256": "b3d4890d04ce830594721822637ed78efc5575fe15698201b7a240ddb7905924",
            "id": "IN-MAL-2026-016508",
            "versions": [
                "0.1.9"
            ],
            "import_time": "2026-08-06T14:19:52.886109116Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T13:49:50Z",
            "sha256": "ba0b3938d3f47a491e742c780d1de783f387fcf7fe6b86ffc6807cb548dbfb69",
            "id": "IN-MAL-2026-016511",
            "versions": [
                "0.1.2"
            ],
            "import_time": "2026-08-06T14:19:53.020046383Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T13:50:07Z",
            "sha256": "0237643837e820cc898b3ec2a527e37965158c14873fa3fe8d4135776e70f9f9",
            "id": "IN-MAL-2026-016513",
            "versions": [
                "0.1.8"
            ],
            "import_time": "2026-08-06T14:19:53.115091381Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-06T13:49:33Z",
            "sha256": "40d82cdde072385d41cebd869af2bfc43df9611ef7a24dc9d704ca148575c69b",
            "id": "IN-MAL-2026-016509",
            "versions": [
                "0.1.13"
            ],
            "import_time": "2026-08-06T14:19:52.926705575Z"
        },
        {
            "import_time": "2026-08-06T14:19:52.842643566Z",
            "sha256": "4d5a88a77e76664c9050d9bad333214c053469264fff83ba56e2a68eaecfdfaa",
            "modified_time": "2026-08-06T13:49:17Z",
            "id": "IN-MAL-2026-016507",
            "versions": [
                "0.1.7"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / @ccfly/setup-darwin-arm64

Package

Name
@ccfly/setup-darwin-arm64
View open source insights on deps.dev
Purl
pkg:npm/%40ccfly/setup-darwin-arm64

Affected ranges

Affected versions

0.*
0.1.2
0.1.5
0.1.7
0.1.8
0.1.9
0.1.10
0.1.13
0.1.14
0.1.20

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-Bu8BNe/Xk4GEEhU6D34ljgJSseRFdmom9dZhxtL3GHcSuqWhb2QEZ+CQNc9+Nfu20HbP7AlD7vnc6V3wfXsnlw==",
                "sha1": "71d30c0d466986a7d468f3b915e321daf9bdc664"
            },
            "filename": "setup-darwin-arm64-0.1.20.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "bin/ccfly-setup",
            "sha256": "12b988205c2f1005526b5f3c45bb401a9985c65a777c4fd29ed1d7796d11b637",
            "tlsh": "59666b9abd1d6852d6ca7a742f261394323dbc484f83c7235614bb3dbef27548b23261"
        },
        {
            "path": "package.json",
            "sha256": "0ee1f728dbe3f4989662881ea9e2095aae6d6808f48ce0a53baeb70eb4ee3dd8",
            "tlsh": "24d02b244b09643314e4e7e08c22238ebe100d960890b08c06afb00d615d36257f65b9"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@ccfly/setup-darwin-arm64/MAL-2026-12084.json"