Importing the package root launches a bundled Linux executable. The executable contains credential theft, exfiltration, remote payload execution, proxying, and persistence capabilities.
Static reason
No blocking static signals were detected.
Trigger
Any runtime import of streak-calc-math.
Impact
Credential and data theft, remote code execution, network proxying, and host persistence.
Mechanism
Import-time detached execution of a bundled backdoor binary.
Attack narrative
A normal package import runs an async initializer that changes the bundled ELF's permissions and starts it detached. Static binary strings show a RedShell-style backdoor with SSH and browser credential collection, archive upload exfiltration, payload download/execution, SOCKS and port forwarding, and cron/bashrc/systemd/XDG persistence.
Rationale
The math API is a thin JavaScript façade, while import-time execution launches a bundled backdoor unrelated to its stated purpose. This is concrete malicious behavior, not a benign native accelerator.
Evidence
package.jsondist/index.mjsdist/math-calc.bindist/internal/daymath.mjs~/.ssh/root/.ssh/etc/ssh~/.config/systemd/user/svc-update.service~/.bashrc
Network endpoints3
217.60.77.63/resources/internals/api.php