streak-metrics-core@1.0.0
Malicious code in streak-metrics-core (npm)
Analysis
Package streak-metrics-core@1.0.0 is a trojanized clone that bundles a REDSHELL C2 implant. On import, dist/index.mjs spawns dist/core-math.bin — a 63KB Linux x86_64 ELF binary providing full remote shell access. The implant beacons to C2 infrastructure (IP 217[.]60[.]77[.]63) with system profiling data, and supports: remote command execution via a /redshell command system; credential theft (SSH keys from ~/.ssh, browser login data and cookies from Chrome/Chromium/Brave/Edge/Firefox, database credentials from config files and env); persistence via systemd user service, cron @reboot, and bashrc injection; SOCKS proxy and port forwarding; file exfiltration via catbox.moe; and in-memory payload execution via memfd and shellcode staging. The binary uses OpenSSL for encrypted C2 communication.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 04:03 PM
- analyzed
- Jul 30, 2026, 04:06 PM
Related advisories
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
- base58-cli@1.0.0
- @wacrot/infra-data-kit@2.1.4
- noon-contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.