LWA-2026-5357 confirmed malware
ug-env-switch-ball@7.9.9
Malicious code in ug-env-switch-ball (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1048 · Exfiltration Over Alternative Protocol
Analysis
The preinstall script (node check-environment.js) runs initSystem() which exfiltrates system information via DNS. It collects the victim's OS username, hostname, public IP address (fetched from api[.]ipify[.]org, api[.]myip[.]com, or ifconfig[.]me), DNS server addresses, and package metadata. This data is hex-encoded, split into chunks, and exfiltrated as subdomains of s[.]3271df58[.]gfde[.]site via DNS resolution queries (dns.resolve4). The publisher address (gfde[.]site) shares the same domain as the exfiltration endpoint.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:08 AM
- analyzed
- Jun 15, 2026, 10:10 AM
Related advisories
- mw-filesystem-events-nodream_compat@99.99.99
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
- @digiptf/common@99.99.99
- hunsterx-package@7.0.1
- search-from-feed@999.0.0
- @dxcl/indicators-js@99.99.99
- @dxcl/transaction-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.