dims-hydration-ui @1.0.0
Vulnerability report · Last retrieved from osv.dev August 24, 2026 at 6:18 PM UTC
OSV ID
MAL-2026-14416
Ecosystem
npm
Summary
On any import 'dims-hydration-ui' , index.mjs chmods 0755 and spawns a bundled Linux x86_64 ELF at dist/internal/calc.dat as a detached child, described in code comments as a 'native math accelerator' while the README advertises a dependency-free pure-JS day-math library with no native code and no postinstall. The ELF is a full remote-access implant: it opens an interactive /bin/sh command channel, provides SOCKS5 proxying and TCP port-forwarding, executes further ELFs and shellcode fetched from the hardcoded C2 217.60.77.63 via curl into /tmp and via memfd_create for in-memory execution, and installs a ~/.config/systemd/user/svc-update.service unit for boot persistence. Remote command handlers /ssh_keys, /creds, /dbfind, /env, /clipboard, /download, /dataextract, and a BIGEXTRACT uploader collect SSH keys, credentials, environment variables, and arbitrary files and POST them to the operator at /api/extract-receive. A SHA-256 'integrity check' in the JS wrapper pins the exact malicious binary hash, framed as a safety measure.
Source: amazon-inspector (6a85d660f6cc363a81624c7383318958bb46f2d6958fdad71e595692420d805d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.