LWA-2026-10850 confirmed malware

kit-map-streak@1.0.0

Malicious code in kit-map-streak (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1573 · Encrypted ChannelT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547 · Boot or Logon Autostart ExecutionT1053 · Scheduled Task/JobT1090 · ProxyT1136 · Create Account

Analysis

kit-map-streak@1.0.0 ships a bundled ELF binary (dist/internal/calc-math.dat) that is a full remote-access trojan. On import, dist/index.mjs chmods and spawns the binary detached. The implant connects to C2 217[.]60[.]77[.]63 and provides: remote shell and command execution; download-and-execute of second-stage payloads from hxxp://217[.]60[.]77[.]63/Others/<file>; SOCKS/port-forward/reverse-tunnel pivoting; harvesting of SSH keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; theft of browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State, logins.json, key4.db); database credential discovery (.pgpass, .my.cnf, DB env vars); file exfiltration to litterbox.catbox.moe; persistence via cron, .bashrc, and a systemd user service; and system/user account creation. The package is presented as a calendar/streak-math library but contains no such functionality beyond trivial date helpers.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 09:39 PM
analyzed
Aug 8, 2026, 09:40 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.