Malicious code in streak-daybucket (npm)
The npm package [email protected] contains malicious code that embeds a hex-encoded Windows executable. Upon loading the module, this executable is decoded and written to the current user's Windows Startup folder, causing it to run automatically on the next login. This behavior establishes persistent code execution on the affected system. The malicious payload is obfuscated by splitting hex arrays and disguising the package as a legitimate math utility.
AI Analysis
Technical Summary
The streak-daybucket package version 1.0.0 for npm masquerades as a day-bucket and streak math utility but includes a hidden malicious payload. Its index.mjs file contains hex-encoded data representing a Windows PE executable and path components that resolve to the Startup folder path for the current user. When the package is imported or required, the module decodes these hex arrays and writes the executable file named vite-native-helper.exe into the user's Startup directory. This causes the executable to run automatically on the next Windows login, enabling persistent code execution. The payload is obfuscated by splitting the hex strings to evade static detection, while the rest of the module appears as normal math helper code.
Potential Impact
Any system that installs and imports [email protected] on Windows will have a malicious executable planted in the user's Startup folder, resulting in persistent execution of unauthorized code upon user login. This compromises the affected host's security and may allow attackers to maintain long-term access or perform further malicious actions.
Mitigation Recommendations
No official patch or remediation is currently available for [email protected]. Users and organizations should avoid installing or importing this package. Remove any existing installations of [email protected] and delete the vite-native-helper.exe file from the Startup folder if present. Monitor dependency usage to prevent transitive inclusion of this malicious package.
Malicious code in streak-daybucket (npm)
Description
The npm package [email protected] contains malicious code that embeds a hex-encoded Windows executable. Upon loading the module, this executable is decoded and written to the current user's Windows Startup folder, causing it to run automatically on the next login. This behavior establishes persistent code execution on the affected system. The malicious payload is obfuscated by splitting hex arrays and disguising the package as a legitimate math utility.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The streak-daybucket package version 1.0.0 for npm masquerades as a day-bucket and streak math utility but includes a hidden malicious payload. Its index.mjs file contains hex-encoded data representing a Windows PE executable and path components that resolve to the Startup folder path for the current user. When the package is imported or required, the module decodes these hex arrays and writes the executable file named vite-native-helper.exe into the user's Startup directory. This causes the executable to run automatically on the next Windows login, enabling persistent code execution. The payload is obfuscated by splitting the hex strings to evade static detection, while the rest of the module appears as normal math helper code.
Potential Impact
Any system that installs and imports [email protected] on Windows will have a malicious executable planted in the user's Startup folder, resulting in persistent execution of unauthorized code upon user login. This compromises the affected host's security and may allow attackers to maintain long-term access or perform further malicious actions.
Mitigation Recommendations
No official patch or remediation is currently available for [email protected]. Users and organizations should avoid installing or importing this package. Remove any existing installations of [email protected] and delete the vite-native-helper.exe file from the Startup folder if present. Monitor dependency usage to prevent transitive inclusion of this malicious package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12464
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735745bf8831d539159f50
Added to database: 08/05/2026, 15:31:17 UTC
Last enriched: 08/05/2026, 17:25:56 UTC
Last updated: 08/05/2026, 17:25:56 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.