streak-metric-core@1.0.0
Malicious code in streak-metric-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1105 · Ingress Tool TransferT1204.002 · Malicious File
Analysis
On module import, streak-metric-core@1.0.0 downloads a remote binary from a Backblaze B2 bucket and executes it as a detached background process. The URL is obfuscated using char-code arrays in dist/index.mjs. The binary is fetched from hxxps://f004[.]backblazeb2[.]com/file/dp8hbvocjd2fpza/service, saved to ~/.cache/streak-metric/service, made executable, and spawned with detached:true and stdio:ignore. The package's stated purpose (calendar-day bucketing and streak math) is unrelated to this behaviour, which is not documented in the README.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 09:25 AM
- analyzed
- Jul 30, 2026, 09:26 AM
Related advisories
- react-fast-refresh-helper@1.2.6
- express-middle@5.5.1
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
- streak-int-lib@1.0.0
- chain-analyze@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.