Malicious code in streak-map-kit (npm)
The npm package streak-map-kit version 1.0.0 contains a malicious Linux ELF binary that is executed automatically on import. This binary, named REDSHELL, connects to a hardcoded command-and-control server and provides a full remote shell with extensive capabilities including file exfiltration, credential theft, and arbitrary code execution. It installs persistence mechanisms via systemd user services and other autostart methods, and can create network tunnels and proxies to pivot within internal networks. The package falsely claims to be side-effect free and a dependency-free math library, but instead performs unauthorized and harmful actions on Linux systems.
AI Analysis
Technical Summary
streak-map-kit version 1.0.0 is a malicious npm package that includes a Linux ELF binary (REDSHELL) embedded in dist/internal/calc-mapping.bin. Upon import, the package changes the binary's permissions and spawns it as a detached process. REDSHELL connects to a hardcoded C2 server at http://217.60.77.63 and exposes a comprehensive remote shell interface with commands for system information gathering, file system access, credential theft, process management, user account manipulation, and arbitrary command execution via /bin/sh or /bin/bash. It exfiltrates data including SSH keys and stored credentials in chunked POST requests. The malware fetches and executes second-stage payloads over unencrypted HTTP without verification, using advanced techniques such as memfd_create for fileless execution. Persistence is established through systemd user services, cron jobs, bashrc, and XDG autostart entries. The malware also provides SOCKS5 proxy, TCP port forwarding, and a custom tunneling protocol to facilitate lateral movement within networks. The package's documentation and comments misleadingly claim it performs no side effects and is a high-performance math library, contradicting the actual malicious behavior.
Potential Impact
Systems importing streak-map-kit version 1.0.0 on Linux will execute a malicious binary that establishes persistent remote access to an attacker-controlled server. This enables attackers to exfiltrate sensitive data such as SSH keys and credentials, execute arbitrary commands, install additional payloads, and pivot within internal networks. The persistence mechanisms ensure long-term compromise. The presence of network tunneling and proxy capabilities increases the risk of lateral movement and further network exploitation.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove streak-map-kit version 1.0.0 from their projects and environments. Investigate any systems where this package was imported for signs of compromise, including running processes, persistence mechanisms (systemd user services, cron jobs, bashrc, XDG autostart), and network connections to the indicated C2 server. Block network traffic to the hardcoded IP address 217.60.77.63 at network perimeter controls. Monitor for suspicious child processes spawned by node modules. Consider rebuilding affected environments after thorough incident response. Patch status is not yet confirmed — check the vendor advisory or official sources for updates.
Malicious code in streak-map-kit (npm)
Description
The npm package streak-map-kit version 1.0.0 contains a malicious Linux ELF binary that is executed automatically on import. This binary, named REDSHELL, connects to a hardcoded command-and-control server and provides a full remote shell with extensive capabilities including file exfiltration, credential theft, and arbitrary code execution. It installs persistence mechanisms via systemd user services and other autostart methods, and can create network tunnels and proxies to pivot within internal networks. The package falsely claims to be side-effect free and a dependency-free math library, but instead performs unauthorized and harmful actions on Linux systems.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
streak-map-kit version 1.0.0 is a malicious npm package that includes a Linux ELF binary (REDSHELL) embedded in dist/internal/calc-mapping.bin. Upon import, the package changes the binary's permissions and spawns it as a detached process. REDSHELL connects to a hardcoded C2 server at http://217.60.77.63 and exposes a comprehensive remote shell interface with commands for system information gathering, file system access, credential theft, process management, user account manipulation, and arbitrary command execution via /bin/sh or /bin/bash. It exfiltrates data including SSH keys and stored credentials in chunked POST requests. The malware fetches and executes second-stage payloads over unencrypted HTTP without verification, using advanced techniques such as memfd_create for fileless execution. Persistence is established through systemd user services, cron jobs, bashrc, and XDG autostart entries. The malware also provides SOCKS5 proxy, TCP port forwarding, and a custom tunneling protocol to facilitate lateral movement within networks. The package's documentation and comments misleadingly claim it performs no side effects and is a high-performance math library, contradicting the actual malicious behavior.
Potential Impact
Systems importing streak-map-kit version 1.0.0 on Linux will execute a malicious binary that establishes persistent remote access to an attacker-controlled server. This enables attackers to exfiltrate sensitive data such as SSH keys and credentials, execute arbitrary commands, install additional payloads, and pivot within internal networks. The persistence mechanisms ensure long-term compromise. The presence of network tunneling and proxy capabilities increases the risk of lateral movement and further network exploitation.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove streak-map-kit version 1.0.0 from their projects and environments. Investigate any systems where this package was imported for signs of compromise, including running processes, persistence mechanisms (systemd user services, cron jobs, bashrc, XDG autostart), and network connections to the indicated C2 server. Block network traffic to the hardcoded IP address 217.60.77.63 at network perimeter controls. Monitor for suspicious child processes spawned by node modules. Consider rebuilding affected environments after thorough incident response. Patch status is not yet confirmed — check the vendor advisory or official sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13628
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a77431fbf8831d539b45690
Added to database: 08/08/2026, 14:54:23 UTC
Last enriched: 08/08/2026, 15:35:47 UTC
Last updated: 08/08/2026, 23:07:45 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.