mnteckets@1.0.1
Malicious code in mnteckets (npm)
T1189 · Drive-by CompromiseT1566.002 · Spearphishing Link
Analysis
mnteckets@1.0.1 ships a single index.html that impersonates a Cloudflare "Performing security verification" Turnstile bot-check page. When a visitor completes the challenge, a heavily obfuscated callback (encoded string array with a custom base64 decoder) assembles a target URL and redirects the browser to it via window.location.href. The package is a phishing redirector: it presents a fake Cloudflare challenge and silently forwards the victim's browser to an attacker-controlled destination. The destination URL is obfuscated inside the encoded string array.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 11:03 AM
- analyzed
- Aug 10, 2026, 11:06 AM
Related advisories
- ms_aidc_com_tw@1.0.0
- ndmckauxuoincv@1.0.0
- fdhcxvnwhjiofv@1.0.0
- dzcvhfruwluwe@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- cloudndmcedu@1.0.0
- ndmcjcxiebysfdb@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.