LWA-2026-10970 confirmed malware

passport811@1.0.0

Malicious code in passport811 (npm)

T1566.002 · Spearphishing LinkT1189 · Drive-by CompromiseT1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols

Analysis

The package ships a single static HTML page that impersonates a Cloudflare "Just a moment..." Turnstile bot-verification challenge. When a visitor completes the fake widget, an obfuscated script redirects the browser to crypt[.]microsoft[.]live/ and forwards the current page's full query-string parameters (commonly OAuth authorization codes, session tokens, and auth state) to that host. The domain impersonates Microsoft and is not a legitimate Microsoft endpoint. This is a phishing redirect kit designed to harvest session credentials from victims who land on it.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 09:22 AM
analyzed
Aug 11, 2026, 09:22 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.