LWA-2026-10095 MAL-2026-12114 ↗ confirmed malware

streak-calc-math@1.0.0

Malicious code in streak-calc-math (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1573 · Encrypted ChannelT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547 · Boot or Logon Autostart ExecutionT1053 · Scheduled Task/JobT1090 · ProxyT1136 · Create Account

Analysis

streak-calc-math@1.0.0 is a trojanized "streak math" library that executes a bundled Linux ELF remote-access implant (dist/math-calc.bin) on import via a detached child process. The implant is a full C2 toolkit: it downloads and executes second-stage ELF/shellcode payloads from C2 host 217[.]60[.]77[.]63 (paths /Others/ and /SC/), establishes reverse tunnels and SOCKS proxies, installs persistence via cron/bashrc/systemd, harvests browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State, logins.json, key4.db) and SSH keys (~/.ssh, /etc/ssh), scans for database credentials (.pgpass, .my.cnf, DB env vars), creates user accounts, and exfiltrates files to the file-upload service litterbox.catbox.moe. It also performs host recon (/sysinfo, /whoami, /ps, /env, /ifconfig, /netstat).

analyzed by
Leitwacht
first seen
Aug 5, 2026, 07:37 AM
analyzed
Aug 5, 2026, 07:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.