twcvhjlksdmx@1.0.0
Malicious code in twcvhjlksdmx (npm)
Analysis
A static HTML page impersonating Cloudflare's "Performing security verification" Turnstile bot-check. The page's JavaScript is obfuscated with a string-array decoder and anti-debug checks; when the Turnstile challenge completes it copies the current page's query-string parameters into an obfuscated destination URL and redirects the browser to it via window.location.href. This is a phishing redirect that forwards the victim's URL parameters to an attacker-controlled destination. The destination URL is obfuscated within the page and not recoverable from static inspection.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 10:02 AM
- analyzed
- Aug 11, 2026, 10:02 AM
Related advisories
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- @coralxyz/anchor@0.30.2
- hardhat-cap@2.21.1
- dolyame-ui-draghoc@35.8.1
- dolyame-ui-tablemobile@35.8.1
- txrand@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.