VDB
KO

MAL-2026-12806

Malicious code in streak-core-bucket (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5e30d02d1e32cea14a74e35046b767fc0f0f5ea6fb5f60958952c2706a8e79c2) On import, the main entry runs a top-level async IIFE that decodes a reversed base64 URL literal to https://f004.backblazeb2.com/file/dp8hbvocjd2fpza/service, downloads the response bytes, writes them to ~/.cache/svc/wsl with mode 0o755, and spawns the file detached with shell:true and stdio ignored. The download URL is concealed via reversed base64 to hide the destination from casual review. The behavior is framed by comments as a benign startup self-check, but the package fetches and executes an opaque remote binary from an anonymous third-party bucket on any require/import of the module.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / streak-core-bucket

No fixed version published yet for streak-core-bucket (npm). Pin to a known-safe version or switch to an alternative.

References