hydration-vli-ui@1.0.0
Malicious code in hydration-vli-ui (npm)
Analysis
hydration-vli-ui@1.0.0 is a trojanized package disguised as calendar/streak math primitives. Importing it spawns a detached native ELF implant (dist/internal/math.mjs) that acts as a remote-access trojan. The implant provides a command-and-control menu including: a reverse shell (/redshell); system recon (/sysinfo, /whoami, /ps, /env, /ifconfig, /netstat); SSH credential harvesting (/ssh_keys — copies ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh id_* keys, authorized_keys, known_hosts, config, and ssh-agent keys); browser credential theft (/creds — Chrome/Chromium/Brave/Edge Login Data, Cookies, Local State, and Firefox logins.json/key4.db); database credential discovery (/dbfind — greps DB configs, ~/.pgpass, ~/.my.cnf, DB env vars); in-memory shellcode execution (/memfd, /shellcode); remote payload download-and-execute (/stage); arbitrary shared-library loading (/dlopen); SOCKS/port-forward/tunnel proxying; persistence via cron, .bashrc, and a systemd user service (/persist); and user account creation (/adduser, /enableuser). Files are exfiltrated to the litterbox.catbox.moe file-upload API (hxxps://litterbox[.]catbox[.]moe/resources/internals/api[.]php).
- analyzed by
- Leitwacht
- first seen
- Aug 26, 2026, 01:00 AM
- analyzed
- Aug 26, 2026, 01:02 AM
Related advisories
- hydration-dim-kit@1.0.0
- kit-map-vim@1.0.0
- kit-map-streak@1.0.0
- streak-calc-math@1.0.0
- dim-hydration-ui@1.0.0
- @wizloft/harness-context@0.1.1-alpha.3
- tailwind-custom-templates@0.7.2
- bnpl-blocks-mobile-bnpl-faq@35.5.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.