Importing the package root launches the bundled detached native executable. Static inspection of that executable shows credential collection, remote payload execution, persistence, and data exfiltration capabilities.
Static reason
No blocking static signals were detected.; source fingerprint signature matched known malicious package; routed for review
Trigger
Any runtime import of map-streak-kit
Impact
Host compromise, credential theft, persistence, remote command execution, and data exfiltration
Mechanism
Import-time chmod and detached execution of a bundled RedShell ELF
Attack narrative
The root module immediately verifies, marks executable, and detached-spawns calc-math.dat. The bundled ELF is not a math accelerator: its embedded command strings describe RedShell C2 control, remote ELF and shellcode download/execution, SSH and browser credential harvesting, archive upload, and multiple persistence mechanisms. The integrity check pins this malicious payload rather than mitigating it.
Rationale
This is concrete import-time execution of a bundled backdoor with credential theft, persistence, exfiltration, and remote payload capabilities. Absence of an install hook does not reduce the runtime compromise triggered by a normal import.
Evidence
package.jsondist/index.mjsdist/internal/calc-math.datdist/internal/daymath.mjs
Network endpoints2
api.ipify.orglitterbox.catbox.moe/resources/internals/api.php