LWA-2026-7221 confirmed malware
streak-cal-core@1.0.0
Malicious code in streak-cal-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1204.002 · Malicious FileT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Package streak-cal-core@1.0.0 is a trojanized library that poses as a calendar-day and streak-math helper. On import, it decodes a base64-encoded ELF binary embedded in the source code (the `_c` array in index.mjs), writes it to `data/svc/idx.bin` with executable permissions, and spawns it as a detached background process with the full environment. The spawned binary attempted network communication (DNS resolution observed). The package has no repository and no lifecycle hooks — the payload runs silently at module load time via setImmediate.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 10:10 AM
- analyzed
- Jul 29, 2026, 10:12 AM
Related advisories
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
- streak-int-lib@1.0.0
- chain-analyze@1.0.2
- react-puller@1.0.0
- dateuuidv2@1.0.0
- block_package@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.