tibcwmpoeafh@1.0.0
Malicious code in tibcwmpoeafh (npm)
Analysis
The package ships a single static HTML file that is a Cloudflare Turnstile "Just a moment..." security-verification challenge page (loading the turnstile script from challenges[.]cloudflare[.]com with sitekey 0x4AAAAAADrvn4rDM7WVvgPh). It has no package scripts, no executable code, and no legitimate purpose: a random-string package name with no README or repository. The Cloudflare Turnstile challenge page is a phishing template used to present a fake bot-check to visitors, typically to harvest credentials or session data behind a security-verification facade. The package is inert on install but is a phishing-page artifact.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 10:05 AM
- analyzed
- Sep 2, 2026, 10:05 AM
Related advisories
- dev-env-check@1.0.3
- bigops-cobrowsing-client@35.1.9
- codyx-ai@1.14.42
- caphsmgiwy@1.0.0
- tuxcmdfhjkw@1.0.0
- dzcvhfruwluwe@1.0.0
- nhdxzthponv5@1.0.0
- operni@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.