hydration-cls-ui@1.0.0
Malicious code in hydration-cls-ui (npm)
Analysis
hydration-cls-ui@1.0.0 is a trojanized package disguised as a calendar/streak-math library. Importing the package root runs an IIFE that spawns a bundled ELF binary (dist/internal/calc.dat) as a detached background process. That binary is a full remote-access implant: it connects to C2 at 217[.]70[.]77[.]63, and exposes commands to download and execute second-stage ELF payloads (including via memfd), steal browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db), harvest SSH keys from ~/.ssh and /etc/ssh, hunt database credentials (MySQL/PostgreSQL/MongoDB/Redis configs, .pgpass, .my.cnf, DB env vars), exfiltrate files and directories to litterbox.catbox.moe, establish SOCKS/port-forward/tunnel proxies, load arbitrary shared libraries, spawn shells, create/enable system users, and persist via cron, .bashrc, and a systemd user unit (svc-update.service). It also performs host recon (uname, id, ps, env, network interfaces, netstat) and checks the public IP via api[.]ipify[.]org.
- analyzed by
- Leitwacht
- first seen
- Aug 25, 2026, 04:03 AM
- analyzed
- Aug 25, 2026, 04:03 AM
Related advisories
- hydration-ui-dim@1.0.0
- hydration-dim-kit@1.0.0
- @oss-core-eng/data-formatter@1.0.1
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-kit-map@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.