streak-kit-map@1.0.0
Malicious code in streak-kit-map (npm)
Analysis
streak-kit-map@1.0.0 is a trojanized calendar/streak-math library. Importing the package spawns a bundled 63KB ELF binary (dist/internal/map-calc.bin) as a detached background process. The binary is a remote-access trojan / C2 implant that connects to C2 IP 217[.]60[.]77[.]63 and provides a reverse-shell command set (/sysinfo, /whoami, /id, /ps, /env, /ifconfig, /netstat, /redshell, /download, /upload, /dataextract, /ssh_keys, /creds, /dbfind, /memfd, /shellcode, /stage, /dlopen, /socks, /portfwd, /tunnel, /kill, /spawn, /adduser, /persist). It harvests SSH private keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; steals browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db); and discovers database credentials (mysql/postgres/mongo/redis configs, ~/.pgpass, ~/.my.cnf, DB env vars). Stolen data is exfiltrated via curl POST to litterbox.catbox.moe. The implant establishes persistence through cron (@reboot), ~/.bashrc, and a systemd user service, and can download and execute remote payloads, stage shellcode via memfd, and set up SOCKS/port-forward/tunnel channels. The advertised day-math functions are implemented in pure JavaScript and do not use the binary.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 08:10 AM
- analyzed
- Aug 7, 2026, 08:11 AM
Related advisories
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- compose-logger-stand@1.0.126
- dolyame-ui-flag@35.7.6
- streak-calc-metrics@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.