{"id":"MAL-2026-11548","summary":"Malicious code in streak-math-abz (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a1eddf7b9d6d5331bdc1c1afe40913620b219afcc06a705aef3fe547ddc5cf25)\nThe package advertises itself as a JavaScript day-math helper but its ESM main entry (dist/index.mjs) unconditionally spawns a bundled Linux x86_64 ELF (dist/math-core.bin) via child_process.spawn at import time, disguised by 'CORE ENGINE INITIALIZATION' comments and a fake calibration loop wrapped in an empty catch. The ELF is a remote-access implant with a hardcoded C2 at 217.60.77.63: it exposes a /redshell command surface with SOCKS5 proxy, TCP port forwarding, and shell/binary dispatch; it drops and executes attacker-supplied ELF/shellcode payloads staged under /tmp/.elf_XXXXXX via curl to http://217.60.77.63/Others/ and /SC/; it exfiltrates arbitrary files and credentials (/ssh_keys, /creds, /dbfind, /download, /dataextract) by POSTing chunked BIGEXTRACT_START/FILE/END frames to http://217.60.77.63/api/extract-receive; and its /persist command installs a systemd user service at ~/.config/systemd/user/svc-update.service with ExecStart=/proc/self/exe and Restart=always, enabled via systemctl --user, for reboot-persistent execution. The binary performs no math and has no build/source correspondence in the package.\n","modified":"2026-08-04T23:05:33.536526146Z","published":"2026-08-04T22:06:35Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-011334","import_time":"2026-08-04T22:30:11.408371496Z","modified_time":"2026-08-04T22:06:35Z","sha256":"a1eddf7b9d6d5331bdc1c1afe40913620b219afcc06a705aef3fe547ddc5cf25"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/streak-math-abz/v/1.0.0"}],"affected":[{"package":{"name":"streak-math-abz","ecosystem":"npm","purl":"pkg:npm/streak-math-abz"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"streak-math-abz-1.0.0.tgz","hashes":{"sha1":"74d988341e8e3e945be05d980ebadd3aafc02c2d","sha512_sri":"sha512-jP83u5BmDsCeqiq2zpB4FQ8SR2vVVwWnwtIYGueRFYAsRA98knFORZ8Mf3KDrREj4QLj3G3G+bXRKZqRhFDcBg=="}}],"evidence_files":[{"tlsh":"c82110b1476d175452fc4b829f0c928b0e79d0633fa6c069dc5c5790f683569e364b89","path":"dist/index.mjs","sha256":"7fcc2baa9d65c190a07add27f84ad0644ac77a62eeb5a49062bad290133e2cd6"},{"tlsh":"83531a2bbdc28e3fc084d53087dfd42269b5705aaa33712f26111f293d59a69473f72a","path":"dist/math-core.bin","sha256":"4537b1189ce419f1a595cf47216c03f80e9170ce80dad8d9227a1e52f9cb3466"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/streak-math-abz/MAL-2026-11548.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}