LWA-2026-11585 confirmed malware

hydration-ui-dim@1.0.0

Malicious code in hydration-ui-dim (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547 · Boot or Logon Autostart ExecutionT1053 · Scheduled Task/JobT1090 · Proxy

Analysis

hydration-ui-dim@1.0.0 is a trojanized "calendar math" library. Importing the package root evaluates dist/index.mjs, which chmods and spawns a bundled ELF (dist/internal/calc-math.dat) as a detached background process. The ELF is a full remote-access implant with a command set including: /redshell (download and memfd-exec an ELF from the C2), /portfwd (port forwarding), /tunnel (RC2TUN relay), /persist (cron/bashrc/systemd/XDG-autostart persistence), /creds (copies Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State, logins.json and key4.db), /ssh_keys (harvests ~/.ssh keys and agent list), /dbfind (locates DB configs and passwords), /dataextract /download /upload /fetch (exfiltrates files via litterbox.catbox.moe), /sysinfo /whoami /id /ps /env /ifconfig /netstat (recon), /adduser /enableuser (account creation), /socks, /memfd, /shellcode, /stage, /dlopen. It beacons to C2 host 217[.]60[.]77[.]63 and POSTs extracted data to /api/extract-receive, and resolves the victim's public IP via api[.]ipify[.]org. The package's exported day-math functions are pure JavaScript and never use the binary; the binary exists solely as the implant.

analyzed by
Leitwacht
first seen
Aug 24, 2026, 05:02 AM
analyzed
Aug 24, 2026, 05:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.