VDB
EN

MAL-2026-12114

Malicious code in streak-calc-math (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e44658b7cae20032e83c5394b65958b61b5e9c4976abe51e4eb28b8056fd86a7) streak-calc-math@1.0.0 bundles a Linux x86_64 ELF at dist/math-calc.bin and launches it unconditionally when the package is imported. The top-level IIFE in dist/index.mjs chmod 0755's the binary and cp.spawn's it detached with piped stdio. A sha256 'integrity verification' against a placeholder constant is a decoy: when the computed hash does not match, execution proceeds anyway; only a log line changes. The ELF is a full RedShell remote-access implant beaconing to hardcoded C2 IP 217.60.77.63 (SECURE_BEACON|...|REDSHELL framing). Operator capabilities include arbitrary shell execution via /bin/sh and /bin/bash, SOCKS5 proxy, TCP port-forward, tunnel relay, and remote payload staging that curls additional ELFs and shellcode over plain HTTP from http://217.60.77.63/Others/ and /SC/ into /tmp or an anonymous memfd (memfd_create syscall 319 invoked via python3 ctypes) and executes them. Operator commands /ssh_keys, /creds, /dbfind, /download, /dataextract and a chunked BIGEXTRACT upload path harvest ~/.ssh keys, credential files, and database files and POST them to http://217.60.77.63/api/extract-receive. Persistence is installed via /redshell persist by writing a user systemd unit at ~/.config/systemd/user/svc-update.service (Description='System Update Service', ExecStart=/proc/self/exe, Restart=always) and enabling it with systemctl --user. The package name and 'high-performance math accelerator' framing are a cover story for a backdoor with no legitimate math functionality.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / streak-calc-math

No fixed version published yet for streak-calc-math (npm). Pin to a known-safe version or switch to an alternative.

참고