LWA-2026-10667 confirmed malware
khanbmnxls@1.0.0
Malicious code in khanbmnxls (npm)
T1071.001 · Web ProtocolsT1567 · Exfiltration Over Web ServiceT1027 · Obfuscated Files or InformationT1059.007 · JavaScript
Analysis
The package ships a single HTML file that impersonates a Cloudflare "Just a moment..." Turnstile verification page. When a visitor solves the Turnstile challenge, the page's obfuscated onTurnstileComplete callback forwards the solved Turnstile token together with the page's URL query parameters to an attacker-controlled host (URL constructed at runtime, beginning with "hxxps://kh"). The page is a CAPTCHA-token and query-string harvesting kit designed to be served to victims.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 03:45 AM
- analyzed
- Aug 7, 2026, 03:46 AM
Related advisories
- weight2loss@1.0.5
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- move-bcs-codec@1.0.0
- streak-map-cache@1.0.0
- mnchfnvbue1@1.0.0
- streak-cache-map@1.0.0
- cnb-cnb-core@35.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.