xsjukcnv8low26@1.0.0
Malicious code in xsjukcnv8low26 (npm)
Analysis
xsjukcnv8low26@1.0.0 ships a single obfuscated index.html that impersonates a Cloudflare Turnstile "Performing security verification" challenge page. It embeds a real Turnstile sitekey and, in the onTurnstileComplete callback, runs a javascript-obfuscator-encoded payload that decodes a base64 string array, constructs a host key and an AES key, and POSTs JSON to a remote host — exfiltrating the solved Turnstile token (and any accompanying data) over an encrypted channel. The C2 destination is concealed inside the obfuscated string array (base64-encoded URL fragments). The package has no functional purpose beyond this token-harvesting page.
- analyzed by
- Leitwacht
- first seen
- Sep 1, 2026, 08:18 AM
- analyzed
- Sep 1, 2026, 08:19 AM
Related advisories
- bamru@1.0.0
- spotify-url-resolvers@3.4.2
- spotify-url-infos@3.4.2
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
- evm-validation@1.0.4
- hydration-dim-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.