LWA-2026-10959 confirmed malware
airdzticket@1.0.0
Malicious code in airdzticket (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package ships a single static HTML file that is a Cloudflare Turnstile "Just a moment..." bot-verification page (loading challenges[.]cloudflare[.]com/turnstile/v0/api.js) and a package.json with no install scripts, no bin entries, and no lifecycle hooks. There is no executable code, no network exfiltration, and no credential access in the package contents.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 08:18 AM
- analyzed
- Aug 11, 2026, 08:19 AM
Related advisories
- ethereum-vault-connector@1.0.0
- @aerodrome-finance/contracts@1.0.0
- camelot-ammv2-core@1.0.0
- @sqlite-labs/nodesql@1.0.5
- chai-as-reformed@1.2.0
- dayjs-advanced@1.2.0
- eth-library-toolkit@2.1.3
- commonjs-assertion@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.