LWA-2026-11560 confirmed malware

hydration-dim-kit@1.0.0

Malicious code in hydration-dim-kit (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1547 · Boot or Logon Autostart ExecutionT1136 · Create AccountT1090 · Proxy

Analysis

hydration-dim-kit@1.0.0 is a trojanized calendar/streak-math library that ships a native Linux ELF remote-access implant as dist/internal/calc.dat. Importing the package root (dist/index.mjs) chmods and spawns this binary detached on every load. The implant provides a remote shell (/redshell), HTTP command-and-control to host 217[.]60[.]77[.]63 with second-stage payload download from hxxp://217[.]60[.]77[.]63:<port>/Others/<file>, SOCKS/port-forward/tunnel proxying, and persistence via cron, ~/.bashrc, and a systemd user service (svc-update.service). It harvests browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db), SSH keys, and database credentials, and exfiltrates collected files to litterbox.catbox.moe and a POST /api/extract-receive endpoint. It can also create/enable local user accounts and stage/execute additional payloads via memfd and shellcode.

analyzed by
Leitwacht
first seen
Aug 23, 2026, 11:16 AM
analyzed
Aug 23, 2026, 11:17 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.