{"id":"MAL-2026-12467","summary":"Malicious code in streak-int-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0acd9bdc8d6474a54b3c985b8472cd50295130d12029de1a8a10175f9be8bb35)\nstreak-int-lib@1.0.0 ships an x86-64 ELF binary as a base64 blob disguised as configuration data (defaultConfig.data joined into embeddedService in index.mjs). On module import, top-level code invokes initializeBackgroundService(), which decodes the blob, writes it to ~/.config/systemd/user/index with mode 0755, and spawns it via child_process.spawn with detached:true, stdio ignored, and proc.unref() so the native process outlives Node. The decoded binary contains TLS/networking symbols (SSL_write, SSL_connect, TLS_client_method, getaddrinfo, gethostname, setsid), indicating a network-capable backgrounded payload. Cover-story comments describe the side effect as a benign 'startup self-check' that 'touches no network and no filesystem', contradicting the observed behavior. The package's declared calendar-math purpose has no need for a bundled ELF or a systemd-path persistence artifact.\n","modified":"2026-08-05T13:36:10.728191231Z","published":"2026-08-05T12:31:12Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T13:08:37.663209819Z","modified_time":"2026-08-05T12:31:12Z","sha256":"0acd9bdc8d6474a54b3c985b8472cd50295130d12029de1a8a10175f9be8bb35","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-014688"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/streak-int-lib/v/1.0.0"}],"affected":[{"package":{"name":"streak-int-lib","ecosystem":"npm","purl":"pkg:npm/streak-int-lib"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"7161fea1d7017f8ee2824550283cc6f4551a42d75f9da3c730bc90808df61831","tlsh":"24935af696873c92a5b11c68d64638082d6c65432139c06afecc63ebb7e5160cf6ecf5","path":"index.mjs"}],"package_integrity":[{"hashes":{"sha1":"93dc678e84a7b80b0f6d2726582ec802632803f9","sha512_sri":"sha512-3GCXV+4UBMcqHbrxjpl6Kk2miMrzdURXQvh6VV44ImrvMqKSAtBo8g1abW6jAbXohI1W3rJYhsLtXuWZ6sSaWg=="},"filename":"streak-int-lib-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/streak-int-lib/MAL-2026-12467.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}