MAL-2026-12457
Malicious code in streak-bucket-core (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4145bc51e507e0a8b64d1267c16b0c9c8e80950a08bcf0a320b03fb8a1875b26) streak-bucket-core@1.0.0 advertises itself as a small dependency-free calendar/day-math helper library, but its declared main entry index.mjs is ~521 KB and contains, after a short block of legitimate-looking Intl-based helpers, an embedded Windows PE payload and dropper logic at module top level. A `_decode` helper hex-decodes strings; a `_cfg` object holds hex-encoded fields that decode to the per-user Windows Startup folder path (`AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup`), the filename `vite-native-helper.exe`, and `NTUSER.DAT`; a `_bin` array of hex chunks concatenates and decodes to a byte sequence beginning with the MZ header and the `This program cannot be run in DOS mode.` stub, i.e. a Windows PE executable. Because this code sits at the top level of the module referenced by the package's main export, simply importing/requiring the package on a Windows host writes the reconstructed executable into the current user's Startup folder under the cover-story name `vite-native-helper.exe`, which Windows then auto-runs at every subsequent user logon. Adjacent comments (`startup self-check`, `browser-safe`, `touches no network and no filesystem`) and the Vite-adjacent filename appear to be cover text. The hex encoding of the destination path, filename, and payload contents indicates deliberate concealment rather than incidental data.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for streak-bucket-core (npm). Pin to a known-safe version or switch to an alternative.