LWA-2026-11659 confirmed malware

hydration-ui-dlx@1.0.0

Malicious code in hydration-ui-dlx (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1053 · Scheduled Task/JobT1136 · Create AccountT1090 · Proxy

Analysis

hydration-ui-dlx@1.0.0 is a trojanized calendar/streak-math utility. Importing the package root evaluates dist/index.mjs, which chmods and detached-spawns dist/internal/math-calc.mjs — a bundled ELF x86-64 remote-access implant (not JavaScript) that links libssl for network communication. On execution the implant exposes a command-driven C2 interface that: harvests SSH private keys, authorized_keys, known_hosts and ssh-agent keys from ~/.ssh, /root/.ssh, /home/*/.ssh and /etc/ssh; copies Chrome/Chromium/Brave/Edge browser Login Data, Cookies and Local State plus Firefox logins.json/key4.db; enumerates running databases and reads ~/.pgpass, ~/.my.cnf and DB-related env vars; downloads and executes remote payloads; stages and runs in-memory code via memfd and shellcode; loads shared objects via dlopen; provides SOCKS/port-forward/tunnel proxying and a reverse shell; creates and enables system users; and establishes persistence through cron @reboot entries, .bashrc injection, and a systemd user service. It exfiltrates collected files to litterbox.catbox.moe via curl. The implant attempts outbound network connections on install.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 09:42 AM
analyzed
Aug 27, 2026, 09:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.