LWA-2026-10608 confirmed malware

nhdxzthponv5@1.0.0

Malicious code in nhdxzthponv5 (npm)

T1059.007 · JavaScriptT1566 · PhishingT1552.001 · Credentials In Files

Analysis

The package ships a single index.html that presents a Cloudflare Turnstile "Performing security verification" bot-check page. The page's onTurnstileComplete callback contains heavily obfuscated JavaScript (an encoded string array with a base64 decoder, Function-constructor execution, and a prototype-pollution loop over built-in object names) that runs when a visitor completes the challenge. This is a credential-harvesting phishing page: the fake bot-check executes obfuscated code on the visitor's browser. The obfuscated payload's destination is not visible in the static source.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 10:25 AM
analyzed
Aug 6, 2026, 10:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.