streak-core-bucket @1.0.0
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12806
Ecosystem
npm
Summary
On import, the main entry runs a top-level async IIFE that decodes a reversed base64 URL literal to https://f004.backblazeb2.com/file/dp8hbvocjd2fpza/service, downloads the response bytes, writes them to ~/.cache/svc/wsl with mode 0o755, and spawns the file detached with shell:true and stdio ignored. The download URL is concealed via reversed base64 to hide the destination from casual review. The behavior is framed by comments as a benign startup self-check, but the package fetches and executes an opaque remote binary from an anonymous third-party bucket on any require/import of the module.
Source: amazon-inspector (5e30d02d1e32cea14a74e35046b767fc0f0f5ea6fb5f60958952c2706a8e79c2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.