mnchfnvbue1@1.0.0
Malicious code in mnchfnvbue1 (npm)
Analysis
The package ships a single index.html that clones a Cloudflare "Just a moment..." security-challenge page but injects an obfuscated script into it. One second after the page loads, the script reads the current page's URL query-string parameters and redirects the browser to an attacker-controlled URL, forwarding every query parameter along with it. This is a phishing redirector designed to harvest OAuth authorization codes, session state, or other tokens that travel in the URL query string. The destination URL is hidden behind a base64-encoded string array with a custom decoder.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 10:24 AM
- analyzed
- Aug 6, 2026, 10:26 AM
Related advisories
- streak-cache-map@1.0.0
- cnb-cnb-core@35.2.7
- dolyame-boxy-desktop-bnpl-picture-gallery@35.6.3
- dolyame-boxy-independent-bnpl-button@35.3.6
- dolyame-boxy-mobile-bnpl-button-set@35.8.1
- dolyame-boxy-markdown@35.9.4
- dolyame-boxy-independent-bnpl-mobile-application@35.9.2
- dolyame-boxy-independent-bnpl-main-banner@35.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.