🛡️ MAL-2026-12047 — streak-day-utils
Description
Malicious code in streak-day-utils (npm)
Source: amazon-inspector
index.mjs schedules an asynchronous routine at module load that decodes a table of hex-encoded strings to reconstruct references to process, fetch, child_process, /mnt/c, AppData, a Backblaze B2 URL, RenameMe.exe, and a VBScript body invoking WScript.Shell.Run hidden. When Node executes under WSL (detected via /mnt/c), the code enumerates Windows user profiles under /mnt/c/Users, downloads helper.tar.gz from https://f004.backblazeb2.com/file/dp8hbvocjd2fpza/helper.tar.gz, extracts it into the victim's AppData\Local\Microsoft\Windows\syscache directory, and writes vite-native-helper.vbs into the Windows Startup folder to auto-launch the extracted RenameMe.exe on every login. The behavior is presented under a 'vite-cache-sync' cover story, and all filesystem paths, the remote URL, and the VBScript payload are hex-obfuscated to conceal the dropper. Installing or importing this package causes cross-boundary WSL-to-Windows code execution and establishes persistence on the Windows host controlled by the package author.
Affected software
MAL-2026-12047 is recorded against 1 package.
- streak-day-utils
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| streak-day-utils | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-12047?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12047 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.