switchpaymentsapiserv-paypal@2.3.4
Malicious code in switchpaymentsapiserv-paypal (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook (preinstall.js) collects the installer's username, hostname, and current working directory, hex-encodes the data, and exfiltrates it via DNS lookup queries to the attacker-controlled domain d9jfvjgl8o8s72utl810ktk61s1xmsysr.o.jgl.red. The data is chunked into 60-character subdomain labels to fit DNS limits, with each chunk sent as a separate dns.lookup() call. The package name mimics a payment-service API (combosquat).
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 12:28 AM
- analyzed
- Jul 30, 2026, 12:28 AM
Related advisories
- @sapappgyver/appgyver-descriptors@9.9.11
- @cybs_forus/test@1.0.0
- @leviosa86com/leviosa86-test@6.0.0
- ap3-components-ui@9.999.0
- @uwr/colors@1.3.6
- wp-codebox-workspace@9999.99.99
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.