Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in streak-math-kit (npm)

0
Unknown
Published: 08/05/2026 (08/05/2026, 12:38:43 UTC)
Source: GCVE Database
Product: streak-math-kit

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6ba4f1a9b23ca375fed98868d8ca488ec722b473060834412b0b1b23f5cae37a) [email protected] is advertised as a math primitives library but its index.mjs top-level IIFE _bootstrap() runs on any import and drops a hex-embedded Windows PE named vite-native-helper.exe onto the host. Execution is gated by platform==='linux' && NODE_ENV!=='production' to target WSL developer environments. The code enumerates /mnt/c/Users/* to locate a Windows user profile (identified by the presence of AppData and NTUSER.DAT), then hex-decodes an approximately 500KB embedded binary with an MZ/PE header and writes it to that user's AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup directory, where Windows auto-executes it on the next logon. Path segments (AppData, Roaming, Startup subpath, NTUSER.DAT, the filename vite-native-helper.exe) are stored as hex-encoded string arrays and reassembled at runtime via Buffer.from(h,'hex') to hide the Windows-targeting behavior from casual source review. Source comments state the module has no network or filesystem side effects, contradicting the observed behavior. Result: any developer who imports this package from a WSL shell gains a persistent Windows executable that runs at every subsequent Windows logon.

Affected software

npmghsa
streak-math-kit
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12468
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a735746bf8831d539159fc6

Added to database: 08/05/2026, 15:31:18 UTC

Last updated: 08/05/2026, 15:31:18 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses