MAL-2026-11527

    Dashboard / Malicious Package / MAL-2026-11527

    MAL-2026-11527

    Published: 4 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in streak-metricsaz (npm)

    Details: Source: amazon-inspector (91054f07d768c0a8605fb644d2cc4003bb6a5d5b9502be2911d9090bc5a37d45) [email protected] presents itself as a calendar/streak math helper but its main entry runs a top-level IIFE that copies a bundled binary (dist/cache.bin) to /tmp/sm-data/w.bin and spawns it via child_process.spawn whenever the module is imported. The dropped file is a Linux x86_64 ELF remote-access implant with a hardcoded C2 at 217.60.77.63, exposing a command menu (/redshell, /persist, /socks, /portfwd, /spawn, /ssh_keys, /creds, /dbfind, /dataextract, /download) that provides interactive shell, SOCKS5 proxy, TCP port-forwarding, memfd download-and-execute of additional ELFs/shellcode, and systemd user-service persistence written as svc-update.service. The implant enumerates and exfiltrates SSH keys, credentials, and arbitrary filesystem paths, uploading via chunked HTTP POST /api/extract-receive to the C2 and via litterbox.catbox.moe. The loader uses deliberately generic identifiers (sm-data, w.bin, cache.bin) and an 'INTERNAL DATA SYNC' comment to disguise the dropper, and swallows errors to run silently.

    Affected packages

    Package

    Name: streak-metricsaz

    Purl: pkg:npm/streak-metricsaz

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-11527 | CVE-DB