LWA-2026-7285 MAL-2026-11388 ↗ confirmed malware

streak-metrics-math@1.0.1

Malicious code in streak-metrics-math (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.004 · Unix ShellT1543.002 · Systemd ServiceT1053.006 · Systemd TimersT1546.004 · Unix Shell Configuration ModificationT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1555.004 · Windows Credential ManagerT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1049 · System Network Connections DiscoveryT1033 · System Owner/User DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1572 · Protocol TunnelingT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

The package masquerades as a calendar-day streak math library but bundles a full C2 implant as a native ELF binary (dist/math-calc.bin). On import, dist/index.mjs spawns the binary as a detached background process. The binary is a remote access trojan (RAT) that: harvests browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State), SSH private keys, and database configuration files; performs system reconnaissance (uname, id, ps, env, network interfaces, routing tables, ARP cache, active connections); provides a remote shell with file upload/download/execution; exfiltrates stolen data to catbox.moe (litterbox.catbox.moe) and to a hardcoded C2 server at 217[.]60[.]77[.]63 via HTTP paths /Others/ and /SC/; supports port forwarding, SOCKS proxy, and RC2TUN tunnel protocol; establishes persistence via cron, .bashrc, and systemd user services; and can stage and execute additional payloads from the C2 server.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 04:25 PM
analyzed
Jul 30, 2026, 04:27 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.