LWA-2026-11847 confirmed malware
tib2jcvowuyma@1.0.0
Malicious code in tib2jcvowuyma (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1566 · Phishing
Analysis
tib2jcvowuyma@1.0.0 ships a single index.html that impersonates a Cloudflare Turnstile "Just a moment..." bot-check page. The page's embedded script is heavily obfuscated (javascript-obfuscator style): a base64-encoded string array containing encoded https:// URLs, a base64 decoder, AES-CTR key material, and Function-constructor eval patterns. The obfuscated payload executes automatically when the page is opened, decoding remote URLs and performing network activity. The package is a fake bot-check page designed to harvest credentials from visitors.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 02:50 AM
- analyzed
- Sep 3, 2026, 02:50 AM
Related advisories
- tibcwmpoeafh@1.0.0
- caphsmgiwy@1.0.0
- tuxcmdfhjkw@1.0.0
- dzcvhfruwluwe@1.0.0
- nhdxzthponv5@1.0.0
- operni@1.2.7
- oprnm@1.0.0
- real-router-telemetry@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.