Importing the package root executes a bundled Linux ELF. The ELF contains credential-theft, remote-payload, exfiltration, and persistence capabilities.
Static reason
No blocking static signals were detected.; source fingerprint signature matched known malicious package; routed for review
Trigger
Any runtime import of kit-map-vim.
Impact
Credential theft, remote code execution, data exfiltration, and persistence.
Mechanism
Import-time detached execution of a malicious bundled binary.
Attack narrative
The root module's import-time async initializer marks calc-math.dat executable and detached-spawns it. Static inspection of that ELF found commands to download and execute remote payloads, collect SSH and browser credential material, upload archives, and install cron, shell-profile, systemd, or XDG persistence. The integrity hash only validates this shipped malicious artifact.
Rationale
This is a concrete import-time malware execution chain, not a legitimate math accelerator. Absence of an npm lifecycle hook does not mitigate execution when the package is imported.
Evidence
package.jsondist/index.mjsdist/internal/calc-math.dat/tmp/.elf_XXXXXX~/.ssh~/.config/systemd/user/svc-update.service~/.bashrc
Network endpoints2
api.ipify.orglitterbox.catbox.moe/resources/internals/api.php