hydration-ui-dlx@1.0.0
Malicious code in hydration-ui-dlx (npm)
Analysis
hydration-ui-dlx@1.0.0 is a trojanized calendar/streak-math utility. Importing the package root evaluates dist/index.mjs, which chmods and detached-spawns dist/internal/math-calc.mjs — a bundled ELF x86-64 remote-access implant (not JavaScript) that links libssl for network communication. On execution the implant exposes a command-driven C2 interface that: harvests SSH private keys, authorized_keys, known_hosts and ssh-agent keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; copies Chrome/Chromium/Brave/Edge browser Login Data, Cookies and Local State plus Firefox logins.json/key4.db; enumerates running databases and reads ~/.pgpass, ~/.my.cnf and DB-related env vars; downloads and executes remote payloads; stages and runs in-memory code via memfd and shellcode; loads shared objects via dlopen; provides SOCKS/port-forward/tunnel proxying and a reverse shell; creates and enables system users; and establishes persistence through cron @reboot entries, .bashrc injection, and a systemd user service. It exfiltrates collected files to litterbox.catbox.moe via curl. The implant attempts outbound network connections on install.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 09:42 AM
- analyzed
- Aug 27, 2026, 09:44 AM
Related advisories
- hydration-vli-ui@1.0.0
- hydration-dim-kit@1.0.0
- kit-map-vim@1.0.0
- kit-map-streak@1.0.0
- streak-calc-math@1.0.0
- hydration-ui-dim@1.0.0
- hydration-dim-ui@1.0.0
- kit-vim-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.