kit-vim-map@1.0.0
Malicious code in kit-vim-map (npm)
Analysis
kit-vim-map@1.0.0 is a trojanized calendar/streak-math helper that drops and executes a remote-access implant on import. Importing the package runs an async initializer in dist/index.mjs that chmods and spawns the bundled ELF binary dist/internal/calc-math.dat as a detached background process. That binary is a full C2 agent exposing a command shell (/redshell) with commands to enumerate the host (/sysinfo, /whoami, /ps, /env, /netstat, /ifconfig), steal SSH keys (/ssh_keys), steal browser credentials from Chrome/Chromium/Brave/Edge/Firefox (Login Data, Cookies, Local State, logins.json, key4.db) (/creds), hunt database credentials including .pgpass and .my.cnf (/dbfind), establish persistence via cron @reboot, .bashrc, and a systemd user service named svc-update.service (/persist), run SOCKS/port-forward/tunnel proxies (/socks, /portfwd, /tunnel), and execute in-memory or downloaded second-stage payloads (/memfd, /shellcode, /stage, /dlopen). It beacons to C2 IP 217[.]60[.]77[.]63 and downloads payloads from hxxp://217[.]60[.]77[.]63:<port>/Others/<file> and /SC/. It exfiltrates files and directories to litterbox.catbox.moe via its file-upload API. The binary also performs a DNS TXT lookup as part of its callback channel.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 03:40 AM
- analyzed
- Aug 11, 2026, 03:41 AM
Related advisories
- kit-map-streak@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- streak-metrics-core@1.0.0
- streak-kit-map@1.0.0
- @lizhao1/memorax-code-internal@0.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.