streak-cache-map@1.0.0
Malicious code in streak-cache-map (npm)
Analysis
The package ships a 63KB Linux ELF binary (dist/internal/calc-cache.bin) that is a remote-access trojan. On import, dist/index.mjs chmods and spawns the binary as a detached background process under a fake "native accelerator" cover story. The binary implements a reverse shell and shellcode/ELF downloader that fetches and executes payloads from hxxp://217[.]60[.]77[.]63/Others/ and hxxp://217[.]60[.]77[.]63/SC/, plus port-forwarding, SOCKS proxy, and tunnel modules. It harvests SSH private keys and authorized_keys from ~/.ssh and /etc/ssh, browser credentials (Chrome/Edge/Brave Login Data, Cookies, Local State; Firefox logins.json and key4.db), and database credentials (.pgpass, .my.cnf, DB config files, DB-related env vars). It installs persistence via cron, .bashrc, and a systemd user service (svc-update.service). It exfiltrates collected files by POSTing them to hxxps://litterbox[.]catbox[.]moe/resources/internals/api[.]php and to a POST /api/extract-receive endpoint. C2 host 217[.]60[.]77[.]63.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 07:55 AM
- analyzed
- Aug 6, 2026, 07:56 AM
Related advisories
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- streak-metrics-core@1.0.0
- streak-map-cache@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
- compose-logger-stand@1.0.126
- streak-kit-map@1.0.0
- dolyame-ui-flag@35.7.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.