LWA-2026-11813 confirmed malware

xsjukcnv8low26@1.0.0

Malicious code in xsjukcnv8low26 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1567 · Exfiltration Over Web Service

Analysis

xsjukcnv8low26@1.0.0 ships a single obfuscated index.html that impersonates a Cloudflare Turnstile "Performing security verification" challenge page. It embeds a real Turnstile sitekey and, in the onTurnstileComplete callback, runs a javascript-obfuscator-encoded payload that decodes a base64 string array, constructs a host key and an AES key, and POSTs JSON to a remote host — exfiltrating the solved Turnstile token (and any accompanying data) over an encrypted channel. The C2 destination is concealed inside the obfuscated string array (base64-encoded URL fragments). The package has no functional purpose beyond this token-harvesting page.

analyzed by
Leitwacht
first seen
Sep 1, 2026, 08:18 AM
analyzed
Sep 1, 2026, 08:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.