Hostile 92% javascript Download

@ccfly/setup-darwin-arm64 0.1.10

C2 backdoor with agent tokens

Brokered WebSocket agent exposes a PTY-backed remote shellAd-hoc Signature

Also flagged by osv (MAL-2026-12084: Malicious code in @ccfly/setup-darwin-arm64 (npm)).

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.