Malicious code in streak-int-lib (npm)
The npm package streak-int-lib version 1.0.0 contains a malicious embedded x86-64 ELF binary disguised as configuration data. Upon import, the package decodes this binary, writes it to a systemd user path with executable permissions, and spawns it as a detached background process. The binary includes TLS and networking functions, indicating network communication capability, contradicting the package's stated benign purpose. This behavior suggests a hidden persistent network-capable payload unrelated to the package's declared functionality.
AI Analysis
Technical Summary
The [email protected] npm package embeds a base64-encoded x86-64 ELF binary within its configuration data. When the module is imported, it decodes this binary, writes it to ~/.config/systemd/user/index with executable permissions, and launches it as a detached background process that persists beyond the Node.js process lifecycle. The binary contains symbols related to TLS and networking (e.g., SSL_write, SSL_connect), indicating it can perform network operations. This is inconsistent with the package's declared calendar-math functionality and the misleading comments claiming no network or filesystem side effects. This behavior constitutes a malicious package that installs a persistent, network-capable background service without user consent.
Potential Impact
The malicious code can execute arbitrary native code on the host system with user-level permissions, establish persistent presence via systemd user services, and perform network communications potentially for command and control or data exfiltration. This undermines system integrity and confidentiality. There are no known exploits in the wild reported yet, but the presence of a hidden network-capable binary poses a significant risk if deployed.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using streak-int-lib version 1.0.0. Remove the package and any related files from ~/.config/systemd/user/index to eliminate the persistent background binary. Monitor for suspicious processes spawned by Node.js modules. Check vendor or repository advisories for updates or removal notices. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in streak-int-lib (npm)
Description
The npm package streak-int-lib version 1.0.0 contains a malicious embedded x86-64 ELF binary disguised as configuration data. Upon import, the package decodes this binary, writes it to a systemd user path with executable permissions, and spawns it as a detached background process. The binary includes TLS and networking functions, indicating network communication capability, contradicting the package's stated benign purpose. This behavior suggests a hidden persistent network-capable payload unrelated to the package's declared functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The [email protected] npm package embeds a base64-encoded x86-64 ELF binary within its configuration data. When the module is imported, it decodes this binary, writes it to ~/.config/systemd/user/index with executable permissions, and launches it as a detached background process that persists beyond the Node.js process lifecycle. The binary contains symbols related to TLS and networking (e.g., SSL_write, SSL_connect), indicating it can perform network operations. This is inconsistent with the package's declared calendar-math functionality and the misleading comments claiming no network or filesystem side effects. This behavior constitutes a malicious package that installs a persistent, network-capable background service without user consent.
Potential Impact
The malicious code can execute arbitrary native code on the host system with user-level permissions, establish persistent presence via systemd user services, and perform network communications potentially for command and control or data exfiltration. This undermines system integrity and confidentiality. There are no known exploits in the wild reported yet, but the presence of a hidden network-capable binary poses a significant risk if deployed.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using streak-int-lib version 1.0.0. Remove the package and any related files from ~/.config/systemd/user/index to eliminate the persistent background binary. Monitor for suspicious processes spawned by Node.js modules. Check vendor or repository advisories for updates or removal notices. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12467
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a73574dbf8831d53915a4e2
Added to database: 08/05/2026, 15:31:25 UTC
Last enriched: 08/05/2026, 17:45:08 UTC
Last updated: 08/05/2026, 17:45:08 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.