npm

dims-hydration-ui @1.0.0

Vulnerability report · Last retrieved from osv.dev August 24, 2026 at 6:18 PM UTC

Malicious

OSV ID

MAL-2026-14416

Ecosystem

npm

Summary

On any import 'dims-hydration-ui' , index.mjs chmods 0755 and spawns a bundled Linux x86_64 ELF at dist/internal/calc.dat as a detached child, described in code comments as a 'native math accelerator' while the README advertises a dependency-free pure-JS day-math library with no native code and no postinstall. The ELF is a full remote-access implant: it opens an interactive /bin/sh command channel, provides SOCKS5 proxying and TCP port-forwarding, executes further ELFs and shellcode fetched from the hardcoded C2 217.60.77.63 via curl into /tmp and via memfd_create for in-memory execution, and installs a ~/.config/systemd/user/svc-update.service unit for boot persistence. Remote command handlers /ssh_keys, /creds, /dbfind, /env, /clipboard, /download, /dataextract, and a BIGEXTRACT uploader collect SSH keys, credentials, environment variables, and arbitrary files and POST them to the operator at /api/extract-receive. A SHA-256 'integrity check' in the JS wrapper pins the exact malicious binary hash, framed as a safety measure.

Source: amazon-inspector (6a85d660f6cc363a81624c7383318958bb46f2d6958fdad71e595692420d805d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.