kit-map-streak@1.0.0
Malicious code in kit-map-streak (npm)
Analysis
kit-map-streak@1.0.0 ships a bundled ELF binary (dist/internal/calc-math.dat) that is a full remote-access trojan. On import, dist/index.mjs chmods and spawns the binary detached. The implant connects to C2 217[.]60[.]77[.]63 and provides: remote shell and command execution; download-and-execute of second-stage payloads from hxxp://217[.]60[.]77[.]63/Others/<file>; SOCKS/port-forward/reverse-tunnel pivoting; harvesting of SSH keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; theft of browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State, logins.json, key4.db); database credential discovery (.pgpass, .my.cnf, DB env vars); file exfiltration to litterbox.catbox.moe; persistence via cron, .bashrc, and a systemd user service; and system/user account creation. The package is presented as a calendar/streak-math library but contains no such functionality beyond trivial date helpers.
- analyzed by
- Leitwacht
- first seen
- Aug 8, 2026, 09:39 PM
- analyzed
- Aug 8, 2026, 09:40 PM
Related advisories
- streak-calc-math@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- streak-math-calc@1.0.0
- streak-metrics-core@1.0.0
- streak-kit-map@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
- compose-logger-stand@1.0.126
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.