LWA-2026-10959 confirmed malware

airdzticket@1.0.0

Malicious code in airdzticket (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The package ships a single static HTML file that is a Cloudflare Turnstile "Just a moment..." bot-verification page (loading challenges[.]cloudflare[.]com/turnstile/v0/api.js) and a package.json with no install scripts, no bin entries, and no lifecycle hooks. There is no executable code, no network exfiltration, and no credential access in the package contents.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 08:18 AM
analyzed
Aug 11, 2026, 08:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.