streak-calc-math@1.0.0
Malicious code in streak-calc-math (npm)
Analysis
streak-calc-math@1.0.0 is a trojanized "streak math" library that executes a bundled Linux ELF remote-access implant (dist/math-calc.bin) on import via a detached child process. The implant is a full C2 toolkit: it downloads and executes second-stage ELF/shellcode payloads from C2 host 217[.]60[.]77[.]63 (paths /Others/ and /SC/), establishes reverse tunnels and SOCKS proxies, installs persistence via cron/bashrc/systemd, harvests browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State, logins.json, key4.db) and SSH keys (~/.ssh, /etc/ssh), scans for database credentials (.pgpass, .my.cnf, DB env vars), creates user accounts, and exfiltrates files to the file-upload service litterbox.catbox.moe. It also performs host recon (/sysinfo, /whoami, /ps, /env, /ifconfig, /netstat).
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 07:37 AM
- analyzed
- Aug 5, 2026, 07:41 AM
Related advisories
- streak-math-calc@1.0.0
- streak-metrics-core@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- compose-logger-stand@1.0.126
- streak-kit-map@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
- system-performance-helper@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.