nhdxzthponv5@1.0.0
Malicious code in nhdxzthponv5 (npm)
Analysis
The package ships a single index.html that presents a Cloudflare Turnstile "Performing security verification" bot-check page. The page's onTurnstileComplete callback contains heavily obfuscated JavaScript (an encoded string array with a base64 decoder, Function-constructor execution, and a prototype-pollution loop over built-in object names) that runs when a visitor completes the challenge. This is a credential-harvesting phishing page: the fake bot-check executes obfuscated code on the visitor's browser. The obfuscated payload's destination is not visible in the static source.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 10:25 AM
- analyzed
- Aug 6, 2026, 10:25 AM
Related advisories
- operni@1.2.7
- oprnm@1.0.0
- streak-cache-map@1.0.0
- app-api-sdk@2.1.7
- app-kst-engine@2.1.6
- dlab_workshop@1.0.3
- @lizhao1/memorax-code-internal@0.1.2
- @zahlen/checkout-react@0.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.