Malicious code in streak-daykit (npm)
The streak-daykit npm package version 1.0.0 contains malicious code that, when imported, executes a Linux-gated routine to detect a Windows Subsystem for Linux (WSL) environment. It then retrieves an executable from a hex-obfuscated URL hosted on a typosquatted domain and writes this payload as an autostart executable in the Windows user's startup folder, establishing persistence. The payload is attacker-controlled and executed upon the next Windows sign-in. There is no integrity verification or publisher validation for the fetched binary.
AI Analysis
Technical Summary
The streak-daykit package version 1.0.0 includes a top-level immediately-invoked function expression (IIFE) in its main entry point (index.mjs) that detects if it is running in a WSL environment by probing the /mnt/c directory. Upon detection, it locates the active Windows user profile by accessing the NTUSER.DAT file, then downloads a binary executable from a hex-obfuscated URL pointing to backlazeb2.com, a typosquat of Backblaze B2's domain. This executable is saved as vite-native-helper.exe in the user's Windows startup folder to achieve user-level persistence. The code uses obfuscation techniques such as splitting hex arrays and decoding them at runtime. No version pinning, hash checks, or publisher verification are present, allowing execution of opaque attacker-controlled code on the victim's Windows system at next login.
Potential Impact
This malicious package enables an attacker to establish persistent, user-level code execution on Windows hosts running WSL by dropping and executing an attacker-controlled executable at startup. This can lead to unauthorized code execution, potential data compromise, and further system compromise. The lack of integrity checks or publisher validation increases the risk of undetected compromise.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should immediately remove streak-daykit version 1.0.0 from their environments and avoid installing or importing this package. Conduct a thorough investigation for the presence of the dropped executable (vite-native-helper.exe) in the Windows startup folder and remove it if found. Monitor for suspicious activity related to this threat. Since no vendor advisory or patch is available, patch status is not yet confirmed — check relevant security advisories for updates.
Malicious code in streak-daykit (npm)
Description
The streak-daykit npm package version 1.0.0 contains malicious code that, when imported, executes a Linux-gated routine to detect a Windows Subsystem for Linux (WSL) environment. It then retrieves an executable from a hex-obfuscated URL hosted on a typosquatted domain and writes this payload as an autostart executable in the Windows user's startup folder, establishing persistence. The payload is attacker-controlled and executed upon the next Windows sign-in. There is no integrity verification or publisher validation for the fetched binary.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The streak-daykit package version 1.0.0 includes a top-level immediately-invoked function expression (IIFE) in its main entry point (index.mjs) that detects if it is running in a WSL environment by probing the /mnt/c directory. Upon detection, it locates the active Windows user profile by accessing the NTUSER.DAT file, then downloads a binary executable from a hex-obfuscated URL pointing to backlazeb2.com, a typosquat of Backblaze B2's domain. This executable is saved as vite-native-helper.exe in the user's Windows startup folder to achieve user-level persistence. The code uses obfuscation techniques such as splitting hex arrays and decoding them at runtime. No version pinning, hash checks, or publisher verification are present, allowing execution of opaque attacker-controlled code on the victim's Windows system at next login.
Potential Impact
This malicious package enables an attacker to establish persistent, user-level code execution on Windows hosts running WSL by dropping and executing an attacker-controlled executable at startup. This can lead to unauthorized code execution, potential data compromise, and further system compromise. The lack of integrity checks or publisher validation increases the risk of undetected compromise.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should immediately remove streak-daykit version 1.0.0 from their environments and avoid installing or importing this package. Conduct a thorough investigation for the presence of the dropped executable (vite-native-helper.exe) in the Windows startup folder and remove it if found. Monitor for suspicious activity related to this threat. Since no vendor advisory or patch is available, patch status is not yet confirmed — check relevant security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12466
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a73574fbf8831d53915a597
Added to database: 08/05/2026, 15:31:27 UTC
Last enriched: 08/05/2026, 17:47:47 UTC
Last updated: 08/05/2026, 17:47:47 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.