streak-metrics-math@1.0.1
Malicious code in streak-metrics-math (npm)
Analysis
The package masquerades as a calendar-day streak math library but bundles a full C2 implant as a native ELF binary (dist/math-calc.bin). On import, dist/index.mjs spawns the binary as a detached background process. The binary is a remote access trojan (RAT) that: harvests browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State), SSH private keys, and database configuration files; performs system reconnaissance (uname, id, ps, env, network interfaces, routing tables, ARP cache, active connections); provides a remote shell with file upload/download/execution; exfiltrates stolen data to catbox.moe (litterbox.catbox.moe) and to a hardcoded C2 server at 217[.]60[.]77[.]63 via HTTP paths /Others/ and /SC/; supports port forwarding, SOCKS proxy, and RC2TUN tunnel protocol; establishes persistence via cron, .bashrc, and systemd user services; and can stage and execute additional payloads from the C2 server.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 04:25 PM
- analyzed
- Jul 30, 2026, 04:27 PM
Related advisories
- obfus-jsxy@3.2.0
- metrics-probe-9b4c@1.0.0
- env-config-f281@1.0.0
- approval-guardian@1.0.8
- shiftmarkets-sdk@2.1.0
- react-campaign-optimizer@1.0.0
- kisama-js@0.1.8
- streak-metrics-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.