LWA-2026-11826 confirmed malware

caphsmgiwy@1.0.0

Malicious code in caphsmgiwy (npm)

T1027 · Obfuscated Files or InformationT1059.007 · JavaScriptT1566 · Phishing

Analysis

caphsmgiwy@1.0.0 is a package with no declared purpose that ships a single index.html disguised as a Cloudflare Turnstile "Performing security verification" challenge page. When a visitor completes the fake challenge, the onTurnstileComplete callback executes a heavily-obfuscated payload (javascript-obfuscator-style _0x identifiers, string-array shuffling, base64 decoding, an AES key, and Function-constructor execution) that decodes and runs encrypted strings. The page is a credential-harvesting/phishing lure: the fake challenge is social engineering to get the victim to interact, after which the obfuscated payload executes. The exfiltration destination is concealed inside the AES-encrypted, base64-encoded strings and is not visible in the plaintext source.

analyzed by
Leitwacht
first seen
Sep 2, 2026, 07:05 AM
analyzed
Sep 2, 2026, 07:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.