caphsmgiwy@1.0.0
Malicious code in caphsmgiwy (npm)
Analysis
caphsmgiwy@1.0.0 is a package with no declared purpose that ships a single index.html disguised as a Cloudflare Turnstile "Performing security verification" challenge page. When a visitor completes the fake challenge, the onTurnstileComplete callback executes a heavily-obfuscated payload (javascript-obfuscator-style _0x identifiers, string-array shuffling, base64 decoding, an AES key, and Function-constructor execution) that decodes and runs encrypted strings. The page is a credential-harvesting/phishing lure: the fake challenge is social engineering to get the victim to interact, after which the obfuscated payload executes. The exfiltration destination is concealed inside the AES-encrypted, base64-encoded strings and is not visible in the plaintext source.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 07:05 AM
- analyzed
- Sep 2, 2026, 07:06 AM
Related advisories
- tuxcmdfhjkw@1.0.0
- dzcvhfruwluwe@1.0.0
- nhdxzthponv5@1.0.0
- operni@1.2.7
- oprnm@1.0.0
- tib2jcvowuyma@1.0.0
- tibcwmpoeafh@1.0.0
- xsjukcnv8low26@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.