LWA-2026-11023 confirmed malware

dzcvhfruwluwe@1.0.0

Malicious code in dzcvhfruwluwe (npm)

T1189 · Drive-by CompromiseT1566 · PhishingT1552.001 · Credentials In Files

Analysis

The package ships a single index.html that clones Cloudflare's "Just a moment..." security-verification page. One second after the page loads, obfuscated JavaScript builds a URL on the attacker-controlled domain ofte[.]live, copies every query parameter from the current page URL onto it, and redirects the browser there. The page is a phishing lure: it impersonates a bot-check to harvest the victim's URL parameters (auth codes/tokens) and forward them to the attacker's domain.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 01:52 AM
analyzed
Aug 12, 2026, 01:52 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.