LWA-2026-11941 confirmed malware
@worrisome/aaaa@1.0.0
Malicious code in @worrisome/aaaa (npm)
T1566 · PhishingT1552 · Unsecured Credentials
Analysis
Ships a single index.html that is a fake Cloudflare "Just a moment..." Turnstile challenge page. The page's inline script is heavily obfuscated (string-array decoder, base64 decoding, an embedded AES key) and, on Turnstile completion, invokes a redirect callback (window.__challengeRedirect) — a phishing-kit pattern used to harvest the Turnstile token and redirect victims to a phishing destination. The package declares no lifecycle scripts, so the page does not execute on npm install, but the shipped artifact is a credential-phishing page.
- analyzed by
- Leitwacht
- first seen
- Sep 8, 2026, 01:46 AM
- analyzed
- Sep 8, 2026, 01:47 AM
Related advisories
- unreal-horde-dashboard@99999.0.0
- hyperpure@1.0.0
- zomato-server@1.0.0
- hex-conv-ae7a@1.0.0
- vaults-monitor-cron@999.0.0
- css-flow-render-shim@1.0.0
- css-reading-display-polyfill@1.0.0
- css-jptvix-polyfill@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.