@ccfly/setup-darwin-arm64 0.1.10
C2 backdoor with agent tokens
Brokered WebSocket agent exposes a PTY-backed remote shellAd-hoc Signature
SHA-2568fc5b164a1d1ccffd6bdf15ec63730e1aff5adaf02149e6bdc1355ab15bb8eae
Also flagged by osv (MAL-2026-12084: Malicious code in @ccfly/setup-darwin-arm64 (npm)).