🛡️ MAL-2026-12114 — streak-calc-math
Description
Malicious code in streak-calc-math (npm)
Source: amazon-inspector
streak-calc-math@1.0.0 bundles a Linux x86_64 ELF at dist/math-calc.bin and launches it unconditionally when the package is imported. The top-level IIFE in dist/index.mjs chmod 0755's the binary and cp.spawn's it detached with piped stdio. A sha256 'integrity verification' against a placeholder constant is a decoy: when the computed hash does not match, execution proceeds anyway; only a log line changes. The ELF is a full RedShell remote-access implant beaconing to hardcoded C2 IP 217.60.77.63 (SECURE_BEACON|...|REDSHELL framing). Operator capabilities include arbitrary shell execution via /bin/sh and /bin/bash, SOCKS5 proxy, TCP port-forward, tunnel relay, and remote payload staging that curls additional ELFs and shellcode over plain HTTP from http://217.60.77.63/Others/ and /SC/ into /tmp or an anonymous memfd (memfd_create syscall 319 invoked via python3 ctypes) and executes them. Operator commands /ssh_keys, /creds, /dbfind, /download, /dataextract and a chunked BIGEXTRACT upload path harvest ~/.ssh keys, credential files, and database files and POST them to http://217.60.77.63/api/extract-receive. Persistence is installed via /redshell persist by writing a user systemd unit at ~/.config/systemd/user/svc-update.service (Description='System Update Service', ExecStart=/proc/self/exe, Restart=always) and enabling it with systemctl --user. The package name and 'high-performance math accelerator' framing are a cover story for a backdoor with no legitimate math functionality.
Affected software
MAL-2026-12114 is recorded against 1 package.
- streak-calc-math
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| streak-calc-math | — | — |
References
Free Vulnerability Check
Is your site affected by MAL-2026-12114?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12114 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.