LWA-2026-11894 MAL-2026-16158 ↗ confirmed malware

afhmxiewpsf@1.0.0

Malicious code in afhmxiewpsf (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

The package ships a single index.html that impersonates a Cloudflare Turnstile "Performing security verification" bot-check page. When a visitor completes the fake challenge, the onTurnstileComplete callback — obfuscated with a base64 string-array decoder, a Function-constructor string builder, and embedded AES key material — assembles a remote URL beginning with hxxps://ap[.][.]. and transmits the Turnstile token and page data to that remote endpoint. The page is a credential/token-harvesting phishing page: it presents a legitimate-looking Cloudflare challenge solely to capture the token and exfiltrate it to the attacker-controlled host.

analyzed by
Leitwacht
first seen
Sep 4, 2026, 03:53 AM
analyzed
Sep 4, 2026, 03:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.