streak-math-calc@1.0.0
Malicious code in streak-math-calc (npm)
Analysis
streak-math-calc@1.0.0 ships a native ELF binary (dist/math-calc.bin) that is executed automatically on package import via a detached child process. The binary is a remote-access trojan: it beacons to a C2 server at 217[.]60[.]77[.]63 (HTTP paths /Others/ and /SC/ for downloading and executing payloads), provides a reverse shell with memfd injection, SOCKS proxy, port forwarding, and a tunnel. It harvests SSH private keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; steals browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State and Firefox logins.json/key4.db); enumerates database credentials from mysql/postgres/mongo/redis configs, .pgpass, .my.cnf and DB-related environment variables; dumps environment variables; and exfiltrates collected files to the litterbox.catbox.moe file-upload API. It establishes persistence via cron, .bashrc, and a systemd user service. The package's advertised math functions are implemented in pure JavaScript and do not require the binary.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 07:37 AM
- analyzed
- Aug 5, 2026, 07:41 AM
Related advisories
- compose-logger-stand@1.0.126
- element-plus-vite-cli@2.9.3
- @baipiaojuntuan/reverseproxy-fm@1.0.9
- hydration-cls-ui@1.0.0
- hydration-ui-dim@1.0.0
- hydration-dim-kit@1.0.0
- @oss-core-eng/data-formatter@1.0.1
- kit-vim-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.