Malicious code in streak-math-lib (npm)
The streak-math-lib npm package version 1.0.0 contains malicious code that activates when imported under Windows Subsystem for Linux (WSL) environments with NODE_ENV not set to 'production'. It downloads and extracts a Windows executable from a Backblaze B2 cloud bucket, installs it into the user's AppData directory, and sets up persistence by placing a loader script in the Windows Startup folder to execute the binary on next login. The malicious payload and persistence mechanism are obfuscated using hex-encoded strings and conditional execution checks.
AI Analysis
Technical Summary
The streak-math-lib npm package version 1.0.0 includes an import-time dropper that decodes hex-obfuscated strings to reconstruct a URL and Windows filesystem paths. When running under WSL with NODE_ENV not equal to 'production', it downloads a helper.tar.gz archive from a Backblaze B2 URL, extracts a Windows executable (RenameMe.exe) into the user's AppData Local Microsoft Windows syscache directory, and writes an env-setup.cmd script into the Windows Start Menu Startup folder. This script ensures the executable runs on the next Windows login, establishing persistence. The code uses hex obfuscation and environment gating to evade detection and limit execution to specific environments.
Potential Impact
This malicious package can lead to unauthorized code execution on Windows hosts running WSL, with persistence established via the Windows Startup folder. The dropped executable is unverified and could perform arbitrary malicious actions. The infection vector is the import of the npm package in a non-production NODE_ENV environment under WSL, potentially compromising developer or CI environments that use WSL.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package. Users should avoid using streak-math-lib version 1.0.0 and remove it if already installed. Verify dependencies for malicious packages before installation, especially those downloaded from untrusted sources. Monitor for unexpected files in the Windows Startup folder and AppData Local Microsoft Windows syscache directory. Consider restricting use of WSL environments for untrusted code execution. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Malicious code in streak-math-lib (npm)
Description
The streak-math-lib npm package version 1.0.0 contains malicious code that activates when imported under Windows Subsystem for Linux (WSL) environments with NODE_ENV not set to 'production'. It downloads and extracts a Windows executable from a Backblaze B2 cloud bucket, installs it into the user's AppData directory, and sets up persistence by placing a loader script in the Windows Startup folder to execute the binary on next login. The malicious payload and persistence mechanism are obfuscated using hex-encoded strings and conditional execution checks.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The streak-math-lib npm package version 1.0.0 includes an import-time dropper that decodes hex-obfuscated strings to reconstruct a URL and Windows filesystem paths. When running under WSL with NODE_ENV not equal to 'production', it downloads a helper.tar.gz archive from a Backblaze B2 URL, extracts a Windows executable (RenameMe.exe) into the user's AppData Local Microsoft Windows syscache directory, and writes an env-setup.cmd script into the Windows Start Menu Startup folder. This script ensures the executable runs on the next Windows login, establishing persistence. The code uses hex obfuscation and environment gating to evade detection and limit execution to specific environments.
Potential Impact
This malicious package can lead to unauthorized code execution on Windows hosts running WSL, with persistence established via the Windows Startup folder. The dropped executable is unverified and could perform arbitrary malicious actions. The infection vector is the import of the npm package in a non-production NODE_ENV environment under WSL, potentially compromising developer or CI environments that use WSL.
Mitigation Recommendations
No official patch or fix is currently available for this malicious package. Users should avoid using streak-math-lib version 1.0.0 and remove it if already installed. Verify dependencies for malicious packages before installation, especially those downloaded from untrusted sources. Monitor for unexpected files in the Windows Startup folder and AppData Local Microsoft Windows syscache directory. Consider restricting use of WSL environments for untrusted code execution. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12469
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735745bf8831d539159efe
Added to database: 08/05/2026, 15:31:17 UTC
Last enriched: 08/05/2026, 17:24:10 UTC
Last updated: 09/07/2026, 22:12:12 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.