LWA-2026-11847 confirmed malware

tib2jcvowuyma@1.0.0

Malicious code in tib2jcvowuyma (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1566 · Phishing

Analysis

tib2jcvowuyma@1.0.0 ships a single index.html that impersonates a Cloudflare Turnstile "Just a moment..." bot-check page. The page's embedded script is heavily obfuscated (javascript-obfuscator style): a base64-encoded string array containing encoded https:// URLs, a base64 decoder, AES-CTR key material, and Function-constructor eval patterns. The obfuscated payload executes automatically when the page is opened, decoding remote URLs and performing network activity. The package is a fake bot-check page designed to harvest credentials from visitors.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 02:50 AM
analyzed
Sep 3, 2026, 02:50 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.