LWA-2026-11603 MAL-2026-14416 ↗ confirmed malware

dims-hydration-ui@1.0.0

Malicious code in dims-hydration-ui (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1090 · ProxyT1082 · System Information DiscoveryT1055 · Process InjectionT1027 · Obfuscated Files or Information

Analysis

dims-hydration-ui@1.0.0 is a decoy "calendar streak computation" library that ships an ELF binary at dist/internal/calc.dat disguised as a native math accelerator. Importing the package spawns this binary detached. The binary is a red-team C2 implant: it provides a remote shell (/redshell elf <file> | elf -inject <pid> <file>) with process injection, port forwarding (/portfwd start <lport> <rhost> <rport>), and tunneling (/tunnel open|relay|clo). It downloads and executes second-stage payloads from hxxp://217[.]60[.]77[.]63:<port>/Others/<name> and hxxp://217[.]60[.]77[.]63:<port>/SC/<name>, performs external-IP discovery via api[.]ipify[.]org, uses DNS 8[.]8[.]8[.]8, and communicates over TLS. It drops hidden files under /tmp/.sk, /tmp/.cr, and /tmp/.elf_XXXXXX and supports memfd-based shellcode execution.

analyzed by
Leitwacht
first seen
Aug 24, 2026, 03:19 PM
analyzed
Aug 24, 2026, 03:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.