ms_aidc_com_tw@1.0.0
Malicious code in ms_aidc_com_tw (npm)
T1566.002 · Spearphishing LinkT1189 · Drive-by Compromise
Analysis
The package ships a single index.html that is a Cloudflare Turnstile "Performing security verification" bot-check interstitial page for the domain ms[.]aidc[.]com[.]tw. The page loads the Cloudflare Turnstile challenge and, on completion, redirects the browser to the target origin. It is a phishing-kit component distributed as an npm package: the package declares no functional code and serves only as a hosted phishing interstitial for the ms[.]aidc[.]com[.]tw domain.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 10:24 AM
- analyzed
- Aug 6, 2026, 10:25 AM
Related advisories
- ndmckauxuoincv@1.0.0
- fdhcxvnwhjiofv@1.0.0
- dzcvhfruwluwe@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- cloudndmcedu@1.0.0
- ndmcjcxiebysfdb@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.