LWA-2026-10630 MAL-2026-13459 ↗ confirmed malware

streak-map-cache@1.0.0

Malicious code in streak-map-cache (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1573 · Encrypted ChannelT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547 · Boot or Logon Autostart ExecutionT1053 · Scheduled Task/JobT1082 · System Information DiscoveryT1090 · Proxy

Analysis

streak-map-cache@1.0.0 is a trojanized utility package. On import, dist/index.mjs chmods and spawns a bundled ELF binary (dist/internal/calc-map.bin) as a detached background process. That binary is a REDSHELL C2 implant: it beacons to a remote controller (SECURE_BEACON format), provides a reverse shell (/bin/sh, /bin/bash), SOCKS/port-forward/tunnel, and a command menu (/redshell, /sysinfo, /ps, /env, /download, /upload, /fetch, /stage, /dlopen, /memfd, /shellcode, /socks, /portfwd, /tunnel, /kill, /spawn). It steals credentials: /creds copies Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies and Local State; /ssh_keys harvests ~/.ssh keys and ssh-agent keys; /dbfind extracts database passwords from configs, ~/.pgpass, ~/.my.cnf and DB env vars. It exfiltrates files via curl POST to litterbox.catbox.moe. It installs persistence via cron, ~/.bashrc, and a systemd user unit (svc-update.service). It downloads and executes second-stage payloads from hxxp://217[.]60[.]77[.]63:%d/Others/%s and stages shellcode via memfd.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 03:24 PM
analyzed
Aug 6, 2026, 03:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.