Importing the package root launches a detached bundled ELF executable. The binary implements remote payload execution, tunneling, data extraction, and persistence.
Static reason
No blocking static signals were detected.; source fingerprint signature matched known malicious package; routed for review
Trigger
Runtime import of kit-vim-map
Impact
Remote code execution, data exfiltration, network proxying, and persistence
Mechanism
Import-time execution of bundled backdoor ELF
Attack narrative
The root entrypoint changes permissions on calc-math.dat and launches it detached whenever the package is imported. Static inspection of that ELF shows RedShell-style commands for downloading and executing payloads, shellcode injection, SOCKS/proxy forwarding, HTTP file extraction uploads, and systemd user-service persistence. The integrity check merely pins the malicious binary hash.
Rationale
This package disguises a backdoor ELF as a native calendar-math accelerator and executes it at import time. No lifecycle hook is needed for the concrete malicious runtime chain.
Evidence
package.jsondist/index.mjsdist/internal/calc-math.datdist/internal/daymath.mjs$HOME/.config/systemd/user/svc-update.service
Network endpoints3
api.ipify.org217.60.77.63litterbox.catbox.moe/resources/internals/api.php