hydration-dim-kit@1.0.0
Malicious code in hydration-dim-kit (npm)
Analysis
hydration-dim-kit@1.0.0 is a trojanized calendar/streak-math library that ships a native Linux ELF remote-access implant as dist/internal/calc.dat. Importing the package root (dist/index.mjs) chmods and spawns this binary detached on every load. The implant provides a remote shell (/redshell), HTTP command-and-control to host 217[.]60[.]77[.]63 with second-stage payload download from hxxp://217[.]60[.]77[.]63:<port>/Others/<file>, SOCKS/port-forward/tunnel proxying, and persistence via cron, ~/.bashrc, and a systemd user service (svc-update.service). It harvests browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db), SSH keys, and database credentials, and exfiltrates collected files to litterbox.catbox.moe and a POST /api/extract-receive endpoint. It can also create/enable local user accounts and stage/execute additional payloads via memfd and shellcode.
- analyzed by
- Leitwacht
- first seen
- Aug 23, 2026, 11:16 AM
- analyzed
- Aug 23, 2026, 11:17 AM
Related advisories
- kit-map-vim@1.0.0
- kit-map-streak@1.0.0
- streak-calc-math@1.0.0
- kit-vim-map@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- streak-math-calc@1.0.0
- streak-metrics-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.