Skip to main content

Malicious code in streak-math-lib (npm)

0
High
Published: 08/05/2026 (08/05/2026, 12:49:43 UTC)
Source: GCVE Database
Product: streak-math-lib

Description

The streak-math-lib npm package version 1.0.0 contains malicious code that activates when imported under Windows Subsystem for Linux (WSL) environments with NODE_ENV not set to 'production'. It downloads and extracts a Windows executable from a Backblaze B2 cloud bucket, installs it into the user's AppData directory, and sets up persistence by placing a loader script in the Windows Startup folder to execute the binary on next login. The malicious payload and persistence mechanism are obfuscated using hex-encoded strings and conditional execution checks.

Affected software

npmghsa
streak-math-lib
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:24:10 UTC

Technical Analysis

The streak-math-lib npm package version 1.0.0 includes an import-time dropper that decodes hex-obfuscated strings to reconstruct a URL and Windows filesystem paths. When running under WSL with NODE_ENV not equal to 'production', it downloads a helper.tar.gz archive from a Backblaze B2 URL, extracts a Windows executable (RenameMe.exe) into the user's AppData Local Microsoft Windows syscache directory, and writes an env-setup.cmd script into the Windows Start Menu Startup folder. This script ensures the executable runs on the next Windows login, establishing persistence. The code uses hex obfuscation and environment gating to evade detection and limit execution to specific environments.

Potential Impact

This malicious package can lead to unauthorized code execution on Windows hosts running WSL, with persistence established via the Windows Startup folder. The dropped executable is unverified and could perform arbitrary malicious actions. The infection vector is the import of the npm package in a non-production NODE_ENV environment under WSL, potentially compromising developer or CI environments that use WSL.

Mitigation Recommendations

No official patch or fix is currently available for this malicious package. Users should avoid using streak-math-lib version 1.0.0 and remove it if already installed. Verify dependencies for malicious packages before installation, especially those downloaded from untrusted sources. Monitor for unexpected files in the Windows Startup folder and AppData Local Microsoft Windows syscache directory. Consider restricting use of WSL environments for untrusted code execution. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12469
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a735745bf8831d539159efe

Added to database: 08/05/2026, 15:31:17 UTC

Last enriched: 08/05/2026, 17:24:10 UTC

Last updated: 09/07/2026, 22:12:12 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses