LWA-2026-11023 confirmed malware
dzcvhfruwluwe@1.0.0
Malicious code in dzcvhfruwluwe (npm)
T1189 · Drive-by CompromiseT1566 · PhishingT1552.001 · Credentials In Files
Analysis
The package ships a single index.html that clones Cloudflare's "Just a moment..." security-verification page. One second after the page loads, obfuscated JavaScript builds a URL on the attacker-controlled domain ofte[.]live, copies every query parameter from the current page URL onto it, and redirects the browser there. The page is a phishing lure: it impersonates a bot-check to harvest the victim's URL parameters (auth codes/tokens) and forward them to the attacker's domain.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 01:52 AM
- analyzed
- Aug 12, 2026, 01:52 AM
Related advisories
- nhdxzthponv5@1.0.0
- operni@1.2.7
- oprnm@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- kit-map-vim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.