afhmxiewpsf@1.0.0
Malicious code in afhmxiewpsf (npm)
Analysis
The package ships a single index.html that impersonates a Cloudflare Turnstile "Performing security verification" bot-check page. When a visitor completes the fake challenge, the onTurnstileComplete callback — obfuscated with a base64 string-array decoder, a Function-constructor string builder, and embedded AES key material — assembles a remote URL beginning with hxxps://ap[.][.]. and transmits the Turnstile token and page data to that remote endpoint. The page is a credential/token-harvesting phishing page: it presents a legitimate-looking Cloudflare challenge solely to capture the token and exfiltrate it to the attacker-controlled host.
- analyzed by
- Leitwacht
- first seen
- Sep 4, 2026, 03:53 AM
- analyzed
- Sep 4, 2026, 03:55 AM
Related advisories
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- @quantixfinance/wallet@1.0.0
- @quantixfinance/common@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.