LWA-2026-10927 confirmed malware

mnteckets@1.0.1

Malicious code in mnteckets (npm)

T1189 · Drive-by CompromiseT1566.002 · Spearphishing Link

Analysis

mnteckets@1.0.1 ships a single index.html that impersonates a Cloudflare "Performing security verification" Turnstile bot-check page. When a visitor completes the challenge, a heavily obfuscated callback (encoded string array with a custom base64 decoder) assembles a target URL and redirects the browser to it via window.location.href. The package is a phishing redirector: it presents a fake Cloudflare challenge and silently forwards the victim's browser to an attacker-controlled destination. The destination URL is obfuscated inside the encoded string array.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 11:03 AM
analyzed
Aug 10, 2026, 11:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.