LWA-2026-10667 confirmed malware

khanbmnxls@1.0.0

Malicious code in khanbmnxls (npm)

T1071.001 · Web ProtocolsT1567 · Exfiltration Over Web ServiceT1027 · Obfuscated Files or InformationT1059.007 · JavaScript

Analysis

The package ships a single HTML file that impersonates a Cloudflare "Just a moment..." Turnstile verification page. When a visitor solves the Turnstile challenge, the page's obfuscated onTurnstileComplete callback forwards the solved Turnstile token together with the page's URL query parameters to an attacker-controlled host (URL constructed at runtime, beginning with "hxxps://kh"). The page is a CAPTCHA-token and query-string harvesting kit designed to be served to victims.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 03:45 AM
analyzed
Aug 7, 2026, 03:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.