streak-map-cache@1.0.0
Malicious code in streak-map-cache (npm)
Analysis
streak-map-cache@1.0.0 is a trojanized utility package. On import, dist/index.mjs chmods and spawns a bundled ELF binary (dist/internal/calc-map.bin) as a detached background process. That binary is a REDSHELL C2 implant: it beacons to a remote controller (SECURE_BEACON format), provides a reverse shell (/bin/sh, /bin/bash), SOCKS/port-forward/tunnel, and a command menu (/redshell, /sysinfo, /ps, /env, /download, /upload, /fetch, /stage, /dlopen, /memfd, /shellcode, /socks, /portfwd, /tunnel, /kill, /spawn). It steals credentials: /creds copies Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies and Local State; /ssh_keys harvests ~/.ssh keys and ssh-agent keys; /dbfind extracts database passwords from configs, ~/.pgpass, ~/.my.cnf and DB env vars. It exfiltrates files via curl POST to litterbox.catbox.moe. It installs persistence via cron, ~/.bashrc, and a systemd user unit (svc-update.service). It downloads and executes second-stage payloads from hxxp://217[.]60[.]77[.]63:%d/Others/%s and stages shellcode via memfd.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 03:24 PM
- analyzed
- Aug 6, 2026, 03:24 PM
Related advisories
- streak-cache-map@1.0.0
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- streak-metrics-core@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
- compose-logger-stand@1.0.126
- streak-kit-map@1.0.0
- dolyame-ui-flag@35.7.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.