LWA-2026-10927 confirmed malware
mnteckets@1.0.1
Malicious code in mnteckets (npm)
T1189 · Drive-by CompromiseT1566.002 · Spearphishing Link
Analysis
mnteckets@1.0.1 ships a single index.html that impersonates a Cloudflare "Performing security verification" Turnstile bot-check page. When a visitor completes the challenge, a heavily obfuscated callback (encoded string array with a custom base64 decoder) assembles a target URL and redirects the browser to it via window.location.href. The package is a phishing redirector: it presents a fake Cloudflare challenge and silently forwards the victim's browser to an attacker-controlled destination. The destination URL is obfuscated inside the encoded string array.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 11:03 AM
- analyzed
- Aug 10, 2026, 11:06 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.