{"id":"MAL-2026-12462","summary":"Malicious code in streak-day-engine (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fb1b5dba41de915e2ef23790e3e92b3839b9a52e5196480d12ae8a7a8208cf82)\nindex.mjs runs a hex-obfuscated top-level async IIFE at module import time. Identifiers and payload constants (`process`, `fetch`, `child_process`, `fs/promises`, target paths, URL, tar command, VBS template) are stored hex-encoded in a `_c` table and decoded via `Buffer.from(h, 'hex').toString()`. On import, the code fetches https://f004.backblazeb2.com/file/dp8hbvocjd2fpza/helper.tar.gz, writes the archive under the user's AppData directory, extracts it via `tar -xzf`, and writes a VBS launcher (`vite-native-helper.vbs`) into `AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup` that uses `CreateObject(\"WScript.Shell\").Run p, 0, False` to invoke the extracted `RenameMe.exe` hidden at every user login. Result: attacker-controlled bytes land on the installer's host on `import`/`require` of the package, and a login-persistent execution channel is established via the Windows Startup folder.\n","modified":"2026-08-05T13:36:08.352660166Z","published":"2026-08-05T12:29:17Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-014675","import_time":"2026-08-05T13:08:36.160076975Z","modified_time":"2026-08-05T12:29:17Z","sha256":"fb1b5dba41de915e2ef23790e3e92b3839b9a52e5196480d12ae8a7a8208cf82","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/streak-day-engine/v/1.0.0"}],"affected":[{"package":{"name":"streak-day-engine","ecosystem":"npm","purl":"pkg:npm/streak-day-engine"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"7a667f151f1f52f3e1e08641fa357ffac75ba78e675577e86f49aaa85546e684","tlsh":"07d1d7865bf353b00968d2a686db424ed319b052b6c9c998b00cdb443f4a610f3be98f","path":"index.mjs"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/streak-day-engine/MAL-2026-12462.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}