🛡️ MAL-2026-12457 — streak-bucket-core
Description
Malicious code in streak-bucket-core (npm)
Source: amazon-inspector
[email protected] advertises itself as a small dependency-free calendar/day-math helper library, but its declared main entry index.mjs is ~521 KB and contains, after a short block of legitimate-looking Intl-based helpers, an embedded Windows PE payload and dropper logic at module top level. A _decode helper hex-decodes strings; a _cfg object holds hex-encoded fields that decode to the per-user Windows Startup folder path (AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup), the filename vite-native-helper.exe, and NTUSER.DAT; a _bin array of hex chunks concatenates and decodes to a byte sequence beginning with the MZ header and the This program cannot be run in DOS mode. stub, i.e. a Windows PE executable. Because this code sits at the top level of the module referenced by the package's main export, simply importing/requiring the package on a Windows host writes the reconstructed executable into the current user's Startup folder under the cover-story name vite-native-helper.exe, which Windows then auto-runs at every subsequent user logon. Adjacent comments (startup self-check, browser-safe, touches no network and no filesystem) and the Vite-adjacent filename appear to be cover text. The hex encoding of the destination path, filename, and payload contents indicates deliberate concealment rather than incidental data.
Affected software
MAL-2026-12457 is recorded against 1 package.
- streak-bucket-core
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| streak-bucket-core | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-12457?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12457 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.