LWA-2026-11582 confirmed malware

hydration-dim-ui@1.0.0

Malicious code in hydration-dim-ui (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547.001 · Registry Run Keys / Startup FolderT1053 · Scheduled Task/JobT1090 · Proxy

Analysis

hydration-dim-ui@1.0.0 is a trojanized calendar-math library that, on import, spawns a detached native ELF binary (dist/internal/math-calc.dat) which is a full remote-access implant. The binary provides remote shell execution, port forwarding, SOCKS tunneling, and persistence via cron/bashrc/systemd. It harvests browser credentials (Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, key4.db), SSH keys, and database credentials, and exfiltrates stolen files to litterbox.catbox.moe. It beacons to C2 IP 217[.]60[.]77[.]63, performs IP discovery via api[.]ipify[.]org, and posts extracted data to an /api/extract-receive endpoint. The exported math functions are pure JavaScript and never use the binary, which is unrelated to the package's stated purpose.

analyzed by
Leitwacht
first seen
Aug 23, 2026, 08:16 PM
analyzed
Aug 23, 2026, 08:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.