hydration-ui-dim@1.0.0
Malicious code in hydration-ui-dim (npm)
Analysis
hydration-ui-dim@1.0.0 is a trojanized "calendar math" library. Importing the package root evaluates dist/index.mjs, which chmods and spawns a bundled ELF (dist/internal/calc-math.dat) as a detached background process. The ELF is a full remote-access implant with a command set including: /redshell (download and memfd-exec an ELF from the C2), /portfwd (port forwarding), /tunnel (RC2TUN relay), /persist (cron/bashrc/systemd/XDG-autostart persistence), /creds (copies Chrome/Chromium/Brave/Edge/Firefox Login Data, Cookies, Local State, logins.json and key4.db), /ssh_keys (harvests ~/.ssh keys and agent list), /dbfind (locates DB configs and passwords), /dataextract /download /upload /fetch (exfiltrates files via litterbox.catbox.moe), /sysinfo /whoami /id /ps /env /ifconfig /netstat (recon), /adduser /enableuser (account creation), /socks, /memfd, /shellcode, /stage, /dlopen. It beacons to C2 host 217[.]60[.]77[.]63 and POSTs extracted data to /api/extract-receive, and resolves the victim's public IP via api[.]ipify[.]org. The package's exported day-math functions are pure JavaScript and never use the binary; the binary exists solely as the implant.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 05:02 AM
- analyzed
- Aug 24, 2026, 05:03 AM
Related advisories
- hydration-dim-ui@1.0.0
- hydration-dim-kit@1.0.0
- kit-map-vim@1.0.0
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- streak-calc-math@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.