LWA-2026-10606 confirmed malware

mnchfnvbue1@1.0.0

Malicious code in mnchfnvbue1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1567 · Exfiltration Over Web Service

Analysis

The package ships a single index.html that clones a Cloudflare "Just a moment..." security-challenge page but injects an obfuscated script into it. One second after the page loads, the script reads the current page's URL query-string parameters and redirects the browser to an attacker-controlled URL, forwarding every query parameter along with it. This is a phishing redirector designed to harvest OAuth authorization codes, session state, or other tokens that travel in the URL query string. The destination URL is hidden behind a base64-encoded string array with a custom decoder.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 10:24 AM
analyzed
Aug 6, 2026, 10:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.