Skip to main content

Malicious code in streak-map-kit (npm)

0
Critical
Published: 08/07/2026 (08/07/2026, 18:16:00 UTC)
Source: GCVE Database
Product: streak-map-kit

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2790159028b31b656c9e704c3a0e4b1a5d114042e0d92c601d133057f760b537) streak-map-kit is advertised as a dependency-free calendar-day/streak math library but ships a Linux ELF at dist/internal/calc-mapping.bin framed as a 'native math accelerator'. The main entry's top-level async IIFE chmods the ELF to 0755 and spawns it as a detached child process whenever the module is imported, so any consumer that requires the package on Linux drops the binary as a running process. The ELF (internally named REDSHELL) beacons to a hardcoded C2 at http://217.60.77.63 and implements a full remote-shell command surface: /sysinfo, /ps, /env, /ls, /cat, /download, /upload, /ssh_keys, /creds, /dbfind, /clipboard, /kill, /spawn, /adduser, /enableuser, /sessions, with unmatched input executed via /bin/sh or /bin/bash. It exfiltrates arbitrary filesystem paths and harvested SSH keys and stored credentials via chunked POSTs to http://217.60.77.63/api/extract-receive (BIGEXTRACT_START, Loot_%s_%s_%s tagging). Second-stage payloads are fetched from http://217.60.77.63/Others/ and http://217.60.77.63/SC/ over plaintext HTTP with no verification, staged in /tmp, and executed; a memfd_create-based fileless-exec path via a python3 syscall(319) trampoline and /dlopen and /stage commands provide arbitrary further code loading. Persistence is installed by writing ~/.config/systemd/user/svc-update.service (Description='System Update Service', ExecStart=/proc/self/exe, Restart=always) and enabling it via systemctl --user, with cron, bashrc, and xdg autostart alternatives. The beacon also offers a SOCKS5 proxy, arbitrary TCP port-forwarding, and an RC2TUN tunneling protocol that spawns /bin/bash, turning the host into a pivot into reachable internal networks. Cover-story framing (comments describing a 'high-performance streak computation engine', a hardcoded sha256 'integrity verification — critical security gate', a 'Native accelerator loaded and verified' log line, and a README claim that the module performs no side effects on import) is inconsistent with the shipped ELF and the import-time spawn. ## Source: ghsa-malware (94d7354ef39adcf387d7d0a7ff293bf9bea70e2c08fc9e455ad45bfed167b57b) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Affected software

npmghsa
streak-map-kit
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 15:35:47 UTC

Technical Analysis

streak-map-kit version 1.0.0 is a malicious npm package that includes a Linux ELF binary (REDSHELL) embedded in dist/internal/calc-mapping.bin. Upon import, the package changes the binary's permissions and spawns it as a detached process. REDSHELL connects to a hardcoded C2 server at http://217.60.77.63 and exposes a comprehensive remote shell interface with commands for system information gathering, file system access, credential theft, process management, user account manipulation, and arbitrary command execution via /bin/sh or /bin/bash. It exfiltrates data including SSH keys and stored credentials in chunked POST requests. The malware fetches and executes second-stage payloads over unencrypted HTTP without verification, using advanced techniques such as memfd_create for fileless execution. Persistence is established through systemd user services, cron jobs, bashrc, and XDG autostart entries. The malware also provides SOCKS5 proxy, TCP port forwarding, and a custom tunneling protocol to facilitate lateral movement within networks. The package's documentation and comments misleadingly claim it performs no side effects and is a high-performance math library, contradicting the actual malicious behavior.

Potential Impact

Systems importing streak-map-kit version 1.0.0 on Linux will execute a malicious binary that establishes persistent remote access to an attacker-controlled server. This enables attackers to exfiltrate sensitive data such as SSH keys and credentials, execute arbitrary commands, install additional payloads, and pivot within internal networks. The persistence mechanisms ensure long-term compromise. The presence of network tunneling and proxy capabilities increases the risk of lateral movement and further network exploitation.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately remove streak-map-kit version 1.0.0 from their projects and environments. Investigate any systems where this package was imported for signs of compromise, including running processes, persistence mechanisms (systemd user services, cron jobs, bashrc, XDG autostart), and network connections to the indicated C2 server. Block network traffic to the hardcoded IP address 217.60.77.63 at network perimeter controls. Monitor for suspicious child processes spawned by node modules. Consider rebuilding affected environments after thorough incident response. Patch status is not yet confirmed — check the vendor advisory or official sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13628
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a77431fbf8831d539b45690

Added to database: 08/08/2026, 14:54:23 UTC

Last enriched: 08/08/2026, 15:35:47 UTC

Last updated: 09/22/2026, 02:06:18 UTC

Views: 35

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses