LWA-2026-10607 confirmed malware

ms_aidc_com_tw@1.0.0

Malicious code in ms_aidc_com_tw (npm)

T1566.002 · Spearphishing LinkT1189 · Drive-by Compromise

Analysis

The package ships a single index.html that is a Cloudflare Turnstile "Performing security verification" bot-check interstitial page for the domain ms[.]aidc[.]com[.]tw. The page loads the Cloudflare Turnstile challenge and, on completion, redirects the browser to the target origin. It is a phishing-kit component distributed as an npm package: the package declares no functional code and serves only as a hosted phishing interstitial for the ms[.]aidc[.]com[.]tw domain.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 10:24 AM
analyzed
Aug 6, 2026, 10:25 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.