LWA-2026-10973 confirmed malware

twcvhjlksdmx@1.0.0

Malicious code in twcvhjlksdmx (npm)

T1566.002 · Spearphishing LinkT1027 · Obfuscated Files or InformationT1189 · Drive-by Compromise

Analysis

A static HTML page impersonating Cloudflare's "Performing security verification" Turnstile bot-check. The page's JavaScript is obfuscated with a string-array decoder and anti-debug checks; when the Turnstile challenge completes it copies the current page's query-string parameters into an obfuscated destination URL and redirects the browser to it via window.location.href. This is a phishing redirect that forwards the victim's URL parameters to an attacker-controlled destination. The destination URL is obfuscated within the page and not recoverable from static inspection.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 10:02 AM
analyzed
Aug 11, 2026, 10:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.