VDB
KO

MAL-2026-12001

Malicious code in streak-metricazbd (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4875da8c750beede70a9031fdd1cf1aa402c49cd94da3abbcd1964a4160a271b) On import of the package, dist/index.mjs runs an IIFE that copies a bundled Linux x86_64 ELF (dist/math-core.bin) to /tmp/sm-engine-runtime/math-core.bin and spawns it via child_process.spawn, framed as 'math-core engine calibration' and wrapped in an error-swallowing try/catch. The dropped binary is a full remote-access implant identifying itself as 'RedShell': it beacons to a hardcoded remote server at 217.60.77.63, accepts commands over that channel to execute arbitrary shell commands via /bin/sh and /bin/bash, provides SOCKS5 proxying and TCP port forwarding, downloads and executes additional ELF/shellcode payloads, installs systemd --user persistence disguised as 'svc-update.service', and exposes /ssh_keys, /creds, /dbfind, /env, /dataextract, and /download commands that harvest installer SSH keys, credentials, and arbitrary files and exfiltrate them in chunks via POST /api/extract-receive. Any host that imports this package hands full remote control and credential access to the operator of 217.60.77.63.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / streak-metricazbd

No fixed version published yet for streak-metricazbd (npm). Pin to a known-safe version or switch to an alternative.

References