LWA-2026-10970 confirmed malware
passport811@1.0.0
Malicious code in passport811 (npm)
T1566.002 · Spearphishing LinkT1189 · Drive-by CompromiseT1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
The package ships a single static HTML page that impersonates a Cloudflare "Just a moment..." Turnstile bot-verification challenge. When a visitor completes the fake widget, an obfuscated script redirects the browser to crypt[.]microsoft[.]live/ and forwards the current page's full query-string parameters (commonly OAuth authorization codes, session tokens, and auth state) to that host. The domain impersonates Microsoft and is not a legitimate Microsoft endpoint. This is a phishing redirect kit designed to harvest session credentials from victims who land on it.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 09:22 AM
- analyzed
- Aug 11, 2026, 09:22 AM
Related advisories
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
- shadxino@1.0.7
- parket-helper@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.