kamafhbnowct@1.0.0
Malicious code in kamafhbnowct (npm)
Analysis
The package ships a single obfuscated index.html that is a fake Cloudflare Turnstile challenge page. It loads the real Cloudflare Turnstile API, collects the visitor's URL query parameters, generates a fabricated ray ID, and renders a fake "Performing security verification" interstitial. The page embeds an AES encryption key and a host key, and the collected visitor/browser data is encrypted before being sent to a remote host. The script is obfuscated with a large encoded string array and custom decoder, hiding the exact collection and exfiltration logic. This is a Turnstile phishing kit designed to harvest Turnstile tokens and visitor data from anyone who loads the page.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 02:05 AM
- analyzed
- Sep 14, 2026, 02:07 AM
Related advisories
- soltinel-pro@0.2.2
- @davidov0516/string-utils@1.1.3
- polygon-toolkits-validator@1.1.4
- @lekzo_dev/amprem@1.0.4
- amprem@1.0.1
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.