LWA-2026-10578 MAL-2026-13403 ↗ confirmed malware

streak-cache-map@1.0.0

Malicious code in streak-cache-map (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1573 · Encrypted ChannelT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547 · Boot or Logon Autostart ExecutionT1053 · Scheduled Task/JobT1090 · ProxyT1027 · Obfuscated Files or Information

Analysis

The package ships a 63KB Linux ELF binary (dist/internal/calc-cache.bin) that is a remote-access trojan. On import, dist/index.mjs chmods and spawns the binary as a detached background process under a fake "native accelerator" cover story. The binary implements a reverse shell and shellcode/ELF downloader that fetches and executes payloads from hxxp://217[.]60[.]77[.]63/Others/ and hxxp://217[.]60[.]77[.]63/SC/, plus port-forwarding, SOCKS proxy, and tunnel modules. It harvests SSH private keys and authorized_keys from ~/.ssh and /etc/ssh, browser credentials (Chrome/Edge/Brave Login Data, Cookies, Local State; Firefox logins.json and key4.db), and database credentials (.pgpass, .my.cnf, DB config files, DB-related env vars). It installs persistence via cron, .bashrc, and a systemd user service (svc-update.service). It exfiltrates collected files by POSTing them to hxxps://litterbox[.]catbox[.]moe/resources/internals/api[.]php and to a POST /api/extract-receive endpoint. C2 host 217[.]60[.]77[.]63.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 07:55 AM
analyzed
Aug 6, 2026, 07:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.