LWA-2026-10094 MAL-2026-12115 ↗ confirmed malware

streak-math-calc@1.0.0

Malicious code in streak-math-calc (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1573 · Encrypted ChannelT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547 · Boot or Logon Autostart ExecutionT1053 · Scheduled Task/JobT1090 · Proxy

Analysis

streak-math-calc@1.0.0 ships a native ELF binary (dist/math-calc.bin) that is executed automatically on package import via a detached child process. The binary is a remote-access trojan: it beacons to a C2 server at 217[.]60[.]77[.]63 (HTTP paths /Others/ and /SC/ for downloading and executing payloads), provides a reverse shell with memfd injection, SOCKS proxy, port forwarding, and a tunnel. It harvests SSH private keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; steals browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State and Firefox logins.json/key4.db); enumerates database credentials from mysql/postgres/mongo/redis configs, .pgpass, .my.cnf and DB-related environment variables; dumps environment variables; and exfiltrates collected files to the litterbox.catbox.moe file-upload API. It establishes persistence via cron, .bashrc, and a systemd user service. The package's advertised math functions are implemented in pure JavaScript and do not require the binary.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 07:37 AM
analyzed
Aug 5, 2026, 07:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.