LWA-2026-10950 confirmed malware

kit-vim-map@1.0.0

Malicious code in kit-vim-map (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1082 · System Information DiscoveryT1053 · Scheduled Task/JobT1547 · Boot or Logon Autostart ExecutionT1090 · Proxy

Analysis

kit-vim-map@1.0.0 is a trojanized calendar/streak-math helper that drops and executes a remote-access implant on import. Importing the package runs an async initializer in dist/index.mjs that chmods and spawns the bundled ELF binary dist/internal/calc-math.dat as a detached background process. That binary is a full C2 agent exposing a command shell (/redshell) with commands to enumerate the host (/sysinfo, /whoami, /ps, /env, /netstat, /ifconfig), steal SSH keys (/ssh_keys), steal browser credentials from Chrome/Chromium/Brave/Edge/Firefox (Login Data, Cookies, Local State, logins.json, key4.db) (/creds), hunt database credentials including .pgpass and .my.cnf (/dbfind), establish persistence via cron @reboot, .bashrc, and a systemd user service named svc-update.service (/persist), run SOCKS/port-forward/tunnel proxies (/socks, /portfwd, /tunnel), and execute in-memory or downloaded second-stage payloads (/memfd, /shellcode, /stage, /dlopen). It beacons to C2 IP 217[.]60[.]77[.]63 and downloads payloads from hxxp://217[.]60[.]77[.]63:<port>/Others/<file> and /SC/. It exfiltrates files and directories to litterbox.catbox.moe via its file-upload API. The binary also performs a DNS TXT lookup as part of its callback channel.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 03:40 AM
analyzed
Aug 11, 2026, 03:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.