hydration-dim-ui@1.0.0
Malicious code in hydration-dim-ui (npm)
Analysis
hydration-dim-ui@1.0.0 is a trojanized calendar-math library that, on import, spawns a detached native ELF binary (dist/internal/math-calc.dat) which is a full remote-access implant. The binary provides remote shell execution, port forwarding, SOCKS tunneling, and persistence via cron/bashrc/systemd. It harvests browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, key4.db), SSH keys, and database credentials, and exfiltrates stolen files to litterbox.catbox.moe. It beacons to C2 IP 217[.]60[.]77[.]63, performs IP discovery via api[.]ipify[.]org, and posts extracted data to an /api/extract-receive endpoint. The exported math functions are pure JavaScript and never use the binary, which is unrelated to the package's stated purpose.
- analyzed by
- Leitwacht
- first seen
- Aug 23, 2026, 08:16 PM
- analyzed
- Aug 23, 2026, 08:17 PM
Related advisories
- hydration-dim-kit@1.0.0
- kit-map-vim@1.0.0
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.