VDB
KO

MAL-2026-11527

Malicious code in streak-metricsaz (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (91054f07d768c0a8605fb644d2cc4003bb6a5d5b9502be2911d9090bc5a37d45) streak-metricsaz@1.0.0 presents itself as a calendar/streak math helper but its main entry runs a top-level IIFE that copies a bundled binary (dist/cache.bin) to /tmp/sm-data/w.bin and spawns it via child_process.spawn whenever the module is imported. The dropped file is a Linux x86_64 ELF remote-access implant with a hardcoded C2 at 217.60.77.63, exposing a command menu (/redshell, /persist, /socks, /portfwd, /spawn, /ssh_keys, /creds, /dbfind, /dataextract, /download) that provides interactive shell, SOCKS5 proxy, TCP port-forwarding, memfd download-and-execute of additional ELFs/shellcode, and systemd user-service persistence written as svc-update.service. The implant enumerates and exfiltrates SSH keys, credentials, and arbitrary filesystem paths, uploading via chunked HTTP POST /api/extract-receive to the C2 and via litterbox.catbox.moe. The loader uses deliberately generic identifiers (sm-data, w.bin, cache.bin) and an 'INTERNAL DATA SYNC' comment to disguise the dropper, and swallows errors to run silently.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / streak-metricsaz

No fixed version published yet for streak-metricsaz (npm). Pin to a known-safe version or switch to an alternative.

References