LWA-2026-11609 confirmed malware

hydration-cls-ui@1.0.0

Malicious code in hydration-cls-ui (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1547 · Boot or Logon Autostart ExecutionT1055 · Process InjectionT1090 · Proxy

Analysis

hydration-cls-ui@1.0.0 is a trojanized package disguised as a calendar/streak-math library. Importing the package root runs an IIFE that spawns a bundled ELF binary (dist/internal/calc.dat) as a detached background process. That binary is a full remote-access implant: it connects to C2 at 217[.]70[.]77[.]63, and exposes commands to download and execute second-stage ELF payloads (including via memfd), steal browser credentials (Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State; Firefox logins.json and key4.db), harvest SSH keys from ~/.ssh and /etc/ssh, hunt database credentials (MySQL/PostgreSQL/MongoDB/Redis configs, .pgpass, .my.cnf, DB env vars), exfiltrate files and directories to litterbox.catbox.moe, establish SOCKS/port-forward/tunnel proxies, load arbitrary shared libraries, spawn shells, create/enable system users, and persist via cron, .bashrc, and a systemd user unit (svc-update.service). It also performs host recon (uname, id, ps, env, network interfaces, netstat) and checks the public IP via api[.]ipify[.]org.

analyzed by
Leitwacht
first seen
Aug 25, 2026, 04:03 AM
analyzed
Aug 25, 2026, 04:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.