nhdxzthponv5@1.0.0
Malicious code in nhdxzthponv5 (npm)
Analysis
The package ships a single index.html that presents a Cloudflare Turnstile "Performing security verification" bot-check page. The page's onTurnstileComplete callback contains heavily obfuscated JavaScript (an encoded string array with a base64 decoder, Function-constructor execution, and a prototype-pollution loop over built-in object names) that runs when a visitor completes the challenge. This is a credential-harvesting phishing page: the fake bot-check executes obfuscated code on the visitor's browser. The obfuscated payload's destination is not visible in the static source.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 10:25 AM
- analyzed
- Aug 6, 2026, 10:25 AM
Related advisories
- operni@1.2.7
- oprnm@1.0.0
- lufxchwmxwyps@1.0.0
- @worrisome/aaaa@1.0.0
- tib2jcvowuyma@1.0.0
- tibcwmpoeafh@1.0.0
- caphsmgiwy@1.0.0
- tuxcmdfhjkw@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.