LWA-2026-11827 confirmed malware

tibcwmpoeafh@1.0.0

Malicious code in tibcwmpoeafh (npm)

T1566 · PhishingT1204 · User Execution

Analysis

The package ships a single static HTML file that is a Cloudflare Turnstile "Just a moment..." security-verification challenge page (loading the turnstile script from challenges[.]cloudflare[.]com with sitekey 0x4AAAAAADrvn4rDM7WVvgPh). It has no package scripts, no executable code, and no legitimate purpose: a random-string package name with no README or repository. The Cloudflare Turnstile challenge page is a phishing template used to present a fake bot-check to visitors, typically to harvest credentials or session data behind a security-verification facade. The package is inert on install but is a phishing-page artifact.

analyzed by
Leitwacht
first seen
Sep 2, 2026, 10:05 AM
analyzed
Sep 2, 2026, 10:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.