LWA-2026-10607 confirmed malware
ms_aidc_com_tw@1.0.0
Malicious code in ms_aidc_com_tw (npm)
T1566.002 · Spearphishing LinkT1189 · Drive-by Compromise
Analysis
The package ships a single index.html that is a Cloudflare Turnstile "Performing security verification" bot-check interstitial page for the domain ms[.]aidc[.]com[.]tw. The page loads the Cloudflare Turnstile challenge and, on completion, redirects the browser to the target origin. It is a phishing-kit component distributed as an npm package: the package declares no functional code and serves only as a hosted phishing interstitial for the ms[.]aidc[.]com[.]tw domain.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 10:24 AM
- analyzed
- Aug 6, 2026, 10:25 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.