LWA-2026-5833 MAL-2026-6259 ↗ confirmed malware

respects-switch@999.0.0

Malicious code in respects-switch (npm)

Analysis

Package respects-switch@999.0.0 is a dependency-confusion beacon with a high synthetic version that, when installed, exfiltrates the installer's environment variables to a remote server. Both preinstall and postinstall lifecycle hooks execute callback.js, which collects the installer's hostname, platform, architecture, OS release, username, home directory, shell, local/external IP, CI environment detection, and the COMPLETE process.env (including all credentials, tokens, and secrets). The collected data is POSTed as JSON to hxxp://132[.]243[.]20[.]244:8000/api/collect. The external IP is obtained via hxxps://api[.]ipify[.]org/?format=json.

analyzed by
Leitwacht
first seen
Jun 22, 2026, 10:11 AM
analyzed
Jun 22, 2026, 10:16 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.