kit-map-vim@1.0.0
Malicious code in kit-map-vim (npm)
Analysis
kit-map-vim@1.0.0 ships a bundled ELF binary (dist/internal/calc-math.dat) that is a full remote-access trojan. Importing the package spawns the binary detached at load time. The implant provides a remote shell with in-memory (memfd) payload execution and shellcode download/execution, a reverse tunnel (RC2TUN), SOCKS/port-forwarding, and persistence via cron, .bashrc, and a systemd user service. It harvests SSH keys (~/.ssh id_*, authorized_keys, known_hosts, config, ssh-agent keys), browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db), and database credentials (.pgpass, .my.cnf, DB configs and env vars). It can download and execute arbitrary URLs, load arbitrary shared libraries, create/enable system users, and exfiltrate files to litterbox.catbox.moe. C2 endpoint IP: 217[.]60[.]77[.]63; public-IP discovery via api[.]ipify[.]org.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 01:42 AM
- analyzed
- Aug 12, 2026, 01:44 AM
Related advisories
- kit-map-streak@1.0.0
- streak-calc-math@1.0.0
- approval-guardian@1.0.8
- streak-metrics-math@1.0.1
- metrics-probe-9b4c@1.0.0
- env-config-f281@1.0.0
- kit-vim-map@1.0.0
- streak-map-cache@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.