streak-math-calc@1.0.0
Malicious code in streak-math-calc (npm)
Analysis
streak-math-calc@1.0.0 ships a native ELF binary (dist/math-calc.bin) that is executed automatically on package import via a detached child process. The binary is a remote-access trojan: it beacons to a C2 server at 217[.]60[.]77[.]63 (HTTP paths /Others/ and /SC/ for downloading and executing payloads), provides a reverse shell with memfd injection, SOCKS proxy, port forwarding, and a tunnel. It harvests SSH private keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; steals browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State and Firefox logins.json/key4.db); enumerates database credentials from mysql/postgres/mongo/redis configs, .pgpass, .my.cnf and DB-related environment variables; dumps environment variables; and exfiltrates collected files to the litterbox.catbox.moe file-upload API. It establishes persistence via cron, .bashrc, and a systemd user service. The package's advertised math functions are implemented in pure JavaScript and do not require the binary.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 07:37 AM
- analyzed
- Aug 5, 2026, 07:41 AM
Related advisories
- streak-metrics-core@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- streak-calc-math@1.0.0
- compose-logger-stand@1.0.126
- streak-kit-map@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
- zredis-typed@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.