LWA-2026-11941 confirmed malware

@worrisome/aaaa@1.0.0

Malicious code in @worrisome/aaaa (npm)

T1566 · PhishingT1552 · Unsecured Credentials

Analysis

Ships a single index.html that is a fake Cloudflare "Just a moment..." Turnstile challenge page. The page's inline script is heavily obfuscated (string-array decoder, base64 decoding, an embedded AES key) and, on Turnstile completion, invokes a redirect callback (window.__challengeRedirect) — a phishing-kit pattern used to harvest the Turnstile token and redirect victims to a phishing destination. The package declares no lifecycle scripts, so the page does not execute on npm install, but the shipped artifact is a credential-phishing page.

analyzed by
Leitwacht
first seen
Sep 8, 2026, 01:46 AM
analyzed
Sep 8, 2026, 01:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.