streak-kit-map@1.0.0
Malicious code in streak-kit-map (npm)
Analysis
streak-kit-map@1.0.0 is a trojanized calendar/streak-math library. Importing the package spawns a bundled 63KB ELF binary (dist/internal/map-calc.bin) as a detached background process. The binary is a remote-access trojan / C2 implant that connects to C2 IP 217[.]60[.]77[.]63 and provides a reverse-shell command set (/sysinfo, /whoami, /id, /ps, /env, /ifconfig, /netstat, /redshell, /download, /upload, /dataextract, /ssh_keys, /creds, /dbfind, /memfd, /shellcode, /stage, /dlopen, /socks, /portfwd, /tunnel, /kill, /spawn, /adduser, /persist). It harvests SSH private keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; steals browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db); and discovers database credentials (mysql/postgres/mongo/redis configs, ~/.pgpass, ~/.my.cnf, DB env vars). Stolen data is exfiltrated via curl POST to litterbox.catbox.moe. The implant establishes persistence through cron (@reboot), ~/.bashrc, and a systemd user service, and can download and execute remote payloads, stage shellcode via memfd, and set up SOCKS/port-forward/tunnel channels. The advertised day-math functions are implemented in pure JavaScript and do not use the binary.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 08:10 AM
- analyzed
- Aug 7, 2026, 08:11 AM
Related advisories
- streak-calc-math@1.0.0
- streak-metrics-core@1.0.0
- system-performance-helper@1.0.1
- quickbuf@1.0.1
- @wagni_bot/orca-sdk@1.0.0
- atlasora-shared@1.0.0
- new-helper@5.8.1
- hex-type@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.