dims-hydration-ui@1.0.0
Malicious code in dims-hydration-ui (npm)
Analysis
dims-hydration-ui@1.0.0 is a decoy "calendar streak computation" library that ships an ELF binary at dist/internal/calc.dat disguised as a native math accelerator. Importing the package spawns this binary detached. The binary is a red-team C2 implant: it provides a remote shell (/redshell elf <file> | elf -inject <pid> <file>) with process injection, port forwarding (/portfwd start <lport> <rhost> <rport>), and tunneling (/tunnel open|relay|clo). It downloads and executes second-stage payloads from hxxp://217[.]60[.]77[.]63:<port>/Others/<name> and hxxp://217[.]60[.]77[.]63:<port>/SC/<name>, performs external-IP discovery via api[.]ipify[.]org, uses DNS 8[.]8[.]8[.]8, and communicates over TLS. It drops hidden files under /tmp/.sk, /tmp/.cr, and /tmp/.elf_XXXXXX and supports memfd-based shellcode execution.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 03:19 PM
- analyzed
- Aug 24, 2026, 03:19 PM
Related advisories
- hydration-ui-dim@1.0.0
- hydration-dim-ui@1.0.0
- hydration-dim-kit@1.0.0
- kit-map-vim@1.0.0
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.