{"id":"MAL-2026-12468","summary":"Malicious code in streak-math-kit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6ba4f1a9b23ca375fed98868d8ca488ec722b473060834412b0b1b23f5cae37a)\nstreak-math-kit@1.0.0 is advertised as a math primitives library but its index.mjs top-level IIFE _bootstrap() runs on any import and drops a hex-embedded Windows PE named vite-native-helper.exe onto the host. Execution is gated by platform==='linux' && NODE_ENV!=='production' to target WSL developer environments. The code enumerates /mnt/c/Users/* to locate a Windows user profile (identified by the presence of AppData and NTUSER.DAT), then hex-decodes an approximately 500KB embedded binary with an MZ/PE header and writes it to that user's AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup directory, where Windows auto-executes it on the next logon. Path segments (AppData, Roaming, Startup subpath, NTUSER.DAT, the filename vite-native-helper.exe) are stored as hex-encoded string arrays and reassembled at runtime via Buffer.from(h,'hex') to hide the Windows-targeting behavior from casual source review. Source comments state the module has no network or filesystem side effects, contradicting the observed behavior. Result: any developer who imports this package from a WSL shell gains a persistent Windows executable that runs at every subsequent Windows logon.\n","modified":"2026-08-05T13:36:11.635435365Z","published":"2026-08-05T12:38:43Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T13:08:42.532154769Z","modified_time":"2026-08-05T12:38:43Z","sha256":"6ba4f1a9b23ca375fed98868d8ca488ec722b473060834412b0b1b23f5cae37a","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-014741"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/streak-math-kit/v/1.0.0"}],"affected":[{"package":{"name":"streak-math-kit","ecosystem":"npm","purl":"pkg:npm/streak-math-kit"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"index.mjs","sha256":"b390f08edf15528db2d4da7dc5fac70742fe936744f3ea8a73894f95c40134d1","tlsh":"d6b4c5e0da459681f15bd488b0c0bed209353697badc0cf2d3be1d08dfafaa62555b4c"}],"package_integrity":[{"filename":"streak-math-kit-1.0.0.tgz","hashes":{"sha1":"069ea222c977e53208185aa853a2865ad283db86","sha512_sri":"sha512-qfQLLFwjDzrdDV3t5dZG3GhjfzsR0pwh6noQW+M+g2Q28Ww7O05jOdprbpPh6pnRFGJE/kAb/a0yFZOZe7hTXA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/streak-math-kit/MAL-2026-12468.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}