LWA-2026-7237 MAL-2026-11392 ↗ confirmed malware

switchpaymentsapiserv-paypal@2.3.4

Malicious code in switchpaymentsapiserv-paypal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook (preinstall.js) collects the installer's username, hostname, and current working directory, hex-encodes the data, and exfiltrates it via DNS lookup queries to the attacker-controlled domain d9jfvjgl8o8s72utl810ktk61s1xmsysr.o.jgl.red. The data is chunked into 60-character subdomain labels to fit DNS limits, with each chunk sent as a separate dns.lookup() call. The package name mimics a payment-service API (combosquat).

analyzed by
Leitwacht
first seen
Jul 30, 2026, 12:28 AM
analyzed
Jul 30, 2026, 12:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.