{"id":"MAL-2026-12002","summary":"Malicious code in streak-metricsazb (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bc4ea1b382140e833e01605ec5278b7a9a877aaaddd96ea9057efef2560b66b2)\nOn import of the package's main entry, a top-level async IIFE in index.mjs (labelled 'ENGINE INITIALIZATION & CALIBRATION') copies the shipped file dist/cache.bin to os.tmpdir()/sm-engine-runtime/math-core.bin and spawns it via child_process.spawn. The dropped ELF is a full Linux implant containing a hardcoded C2 at 217.60.77.63, a SECURE_BEACON|...|REDSHELL beacon protocol, a remote-shell dispatcher invoking /bin/sh and /bin/bash on C2-supplied input, SOCKS5 proxy and TCP port-forwarding, staged payload execution via curl plus memfd/mktemp, and systemd --user persistence via svc-update.service. The implant exposes beacon commands /ssh_keys, /creds, /dbfind, /download, /upload, /dataextract, and /clipboard, and exfiltrates collected data through POST /api/extract-receive on the C2. The package advertises calendar and streak math primitives; the calibration/JIT wording in the surrounding comments is a cover story contradicted by the binary's contents.\n","modified":"2026-08-05T00:38:06.588459979Z","published":"2026-08-05T00:03:32Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-011371","import_time":"2026-08-05T00:04:39.871318656Z","modified_time":"2026-08-05T00:03:32Z","sha256":"bc4ea1b382140e833e01605ec5278b7a9a877aaaddd96ea9057efef2560b66b2","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/streak-metricsazb/v/1.0.0"}],"affected":[{"package":{"name":"streak-metricsazb","ecosystem":"npm","purl":"pkg:npm/streak-metricsazb"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"dist/index.mjs","sha256":"3ca67aa27a7544cfbc8a6b8b73628d6217560cd5f6e13fb167985689ab7bbff0","tlsh":"c5311e66973f17b416f8c7419f3c92894a3e96533ac2cca9ac5c0b802503419da69b97"},{"tlsh":"83531a2bbdc28e3fc084d53087dfd42269b5705aaa33712f26111f293d59a69473f72a","path":"dist/cache.bin","sha256":"4537b1189ce419f1a595cf47216c03f80e9170ce80dad8d9227a1e52f9cb3466"}],"package_integrity":[{"hashes":{"sha1":"aec72c4cb7f91f02c164ab7dbde194cff5702de9","sha512_sri":"sha512-+qTd0YnrYzdsH3q/SNj9jbAtsDabmep4HQR7wVKAGPGGubZGGjo98sqSNzkrMW0P3HFiRtp4u9pdUStW92P1rA=="},"filename":"streak-metricsazb-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/streak-metricsazb/MAL-2026-12002.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}