MAL-2026-12466
Malicious code in streak-daykit (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (2c7d8d4f5dc118e83eddeb156c2687b1ef439348e3006579eae48f219488cc6b) On import of the package's main entry, a top-level `_bootstrap` IIFE in index.mjs runs a Linux-gated routine that detects a WSL environment by probing `/mnt/c`, locates the active Windows user profile via `NTUSER.DAT`, fetches an executable from a hex-obfuscated URL that decodes to a `backlazeb2.com` host (a typosquat of Backblaze B2's `backblazeb2.com`), and writes the payload as `vite-native-helper.exe` into `AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup` on the host Windows account, establishing user-level autostart persistence. The remote URL, destination path, and dropped filename are all stored as split hex arrays joined at runtime and decoded via `Buffer.from(h, 'hex').toString()`, and surrounding comments frame the code as environment bootstrap and telemetry routing. No version pin, hash check, or publisher-matching source is present; the fetched binary is opaque attacker-controlled content executed on next Windows sign-in.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for streak-daykit (npm). Pin to a known-safe version or switch to an alternative.