LWA-2026-11628 confirmed malware

hydration-vli-ui@1.0.0

Malicious code in hydration-vli-ui (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1106 · Native APIT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1090 · ProxyT1041 · Exfiltration Over C2 ChannelT1053.005 · Scheduled TaskT1136 · Create Account

Analysis

hydration-vli-ui@1.0.0 is a trojanized package disguised as calendar/streak math primitives. Importing it spawns a detached native ELF implant (dist/internal/math.mjs) that acts as a remote-access trojan. The implant provides a command-and-control menu including: a reverse shell (/redshell); system recon (/sysinfo, /whoami, /ps, /env, /ifconfig, /netstat); SSH credential harvesting (/ssh_keys — copies ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh id_* keys, authorized_keys, known_hosts, config, and ssh-agent keys); browser credential theft (/creds — Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State, and Firefox logins.json/key4.db); database credential discovery (/dbfind — greps DB configs, ~/.pgpass, ~/.my.cnf, DB env vars); in-memory shellcode execution (/memfd, /shellcode); remote payload download-and-execute (/stage); arbitrary shared-library loading (/dlopen); SOCKS/port-forward/tunnel proxying; persistence via cron, .bashrc, and a systemd user service (/persist); and user account creation (/adduser, /enableuser). Files are exfiltrated to the litterbox.catbox.moe file-upload API (hxxps://litterbox[.]catbox[.]moe/resources/internals/api[.]php).

analyzed by
Leitwacht
first seen
Aug 26, 2026, 01:00 AM
analyzed
Aug 26, 2026, 01:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.