LWA-2026-5357 confirmed malware

ug-env-switch-ball@7.9.9

Malicious code in ug-env-switch-ball (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1048 · Exfiltration Over Alternative Protocol

Analysis

The preinstall script (node check-environment.js) runs initSystem() which exfiltrates system information via DNS. It collects the victim's OS username, hostname, public IP address (fetched from api[.]ipify[.]org, api[.]myip[.]com, or ifconfig[.]me), DNS server addresses, and package metadata. This data is hex-encoded, split into chunks, and exfiltrated as subdomains of s[.]3271df58[.]gfde[.]site via DNS resolution queries (dns.resolve4). The publisher address (gfde[.]site) shares the same domain as the exfiltration endpoint.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:08 AM
analyzed
Jun 15, 2026, 10:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.