luftzxyuiwgbgsp@1.0.0
Malicious code in luftzxyuiwgbgsp (npm)
T1566.002 · Spearphishing LinkT1059.007 · JavaScript
Analysis
The package ships a single obfuscated index.html that impersonates a Cloudflare "Just a moment..." Turnstile bot-check page. The page is obfuscated with a large encoded string array and a custom decoder, embeds hostKey/aesKeyBase64/turnstileSiteKey constants, reads the visitor's URL query parameters, and on Turnstile completion invokes a __challengeRedirect handler that redirects the visitor to a phishing destination. It is a credential-harvesting page designed to trick users into completing a fake challenge and being redirected to a malicious site.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 03:50 AM
- analyzed
- Sep 10, 2026, 03:51 AM
Related advisories
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- cloudndmcedu@1.0.0
- ndmcjcxiebysfdb@1.0.0
- luftmvfiwgxydes@1.0.0
- soltinel-pro@0.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.