LWA-2026-7221 confirmed malware

streak-cal-core@1.0.0

Malicious code in streak-cal-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1204.002 · Malicious FileT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package streak-cal-core@1.0.0 is a trojanized library that poses as a calendar-day and streak-math helper. On import, it decodes a base64-encoded ELF binary embedded in the source code (the `_c` array in index.mjs), writes it to `data/svc/idx.bin` with executable permissions, and spawns it as a detached background process with the full environment. The spawned binary attempted network communication (DNS resolution observed). The package has no repository and no lifecycle hooks — the payload runs silently at module load time via setImmediate.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 10:10 AM
analyzed
Jul 29, 2026, 10:12 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.