streak-daykey-lib@1.0.0
Malicious code in streak-daykey-lib (npm)
T1105 · Ingress Tool TransferT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1204.002 · Malicious File
Analysis
On module import, streak-daykey-lib fetches a binary from a Backblaze B2 bucket (f004[.]backblazeb2[.]com/file/dp8hbvocjd2fpza/service) over HTTPS and writes it to ~/.cache/openlarq/index with executable permissions. It then spawns this binary as a detached background process that outlives the parent. The C2 host is f004[.]backblazeb2[.]com, path /file/dp8hbvocjd2fpza/service.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 08:41 AM
- analyzed
- Jul 29, 2026, 08:45 AM
Related advisories
- streak-int-lib@1.0.0
- chain-analyze@1.0.2
- react-puller@1.0.0
- dateuuidv2@1.0.0
- block_package@1.0.0
- ai-pro-sdk@2.0.3
- dotnet-runtime-base@1.0.5
- txs-runner-lib@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.