streak-math-metrics@1.0.0
Malicious code in streak-math-metrics (npm)
Analysis
streak-math-metrics@1.0.0 is a trojanized package that ships a bundled ELF binary (dist/math-calc.bin) which is a full remote-access trojan. On import, the package spawns the binary as a detached background process. The binary provides: remote shell execution, TCP port forwarding, SSH key theft (from ~/.ssh/), browser credential harvesting (Chrome, Firefox, Brave, Edge — Login Data, Cookies, Local State), database discovery, file exfiltration to hardcoded C2 at 217[.]60[.]77[.]63 and to catbox.moe, and systemd user-service persistence. The binary also performs DNS reconnaissance and system information gathering.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 04:09 PM
- analyzed
- Jul 30, 2026, 04:10 PM
Related advisories
- system-performance-helper@1.0.1
- json-validator-utils@1.0.1
- chunk-parser@1.0.0
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
- zod-pino434@1.0.127
- nat-ulid@3.0.2
- check-ulid@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.