LWA-2026-5357 confirmed malware
ug-env-switch-ball@7.9.9
Malicious code in ug-env-switch-ball (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1048 · Exfiltration Over Alternative Protocol
Analysis
The preinstall script (node check-environment.js) runs initSystem() which exfiltrates system information via DNS. It collects the victim's OS username, hostname, public IP address (fetched from api[.]ipify[.]org, api[.]myip[.]com, or ifconfig[.]me), DNS server addresses, and package metadata. This data is hex-encoded, split into chunks, and exfiltrated as subdomains of s[.]3271df58[.]gfde[.]site via DNS resolution queries (dns.resolve4). The publisher address (gfde[.]site) shares the same domain as the exfiltration endpoint.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:08 AM
- analyzed
- Jun 15, 2026, 10:10 AM
Related advisories
- mw-filesystem-events-nodream_compat@99.99.99
- @nf-addons/am-global-header@9.9.10
- @tvg-mar/tvg-promos-atomic-ui@9.9.10
- siriusbeyond@1.0.0
- @hzero-front-ui/hzero-ui@99.99.99
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
- @digiptf/common@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.