LWA-2026-12088 MAL-2026-16450 ↗ confirmed malware

kamafhbnowct@1.0.0

Malicious code in kamafhbnowct (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1567 · Exfiltration Over Web Service

Analysis

The package ships a single obfuscated index.html that is a fake Cloudflare Turnstile challenge page. It loads the real Cloudflare Turnstile API, collects the visitor's URL query parameters, generates a fabricated ray ID, and renders a fake "Performing security verification" interstitial. The page embeds an AES encryption key and a host key, and the collected visitor/browser data is encrypted before being sent to a remote host. The script is obfuscated with a large encoded string array and custom decoder, hiding the exact collection and exfiltration logic. This is a Turnstile phishing kit designed to harvest Turnstile tokens and visitor data from anyone who loads the page.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 02:05 AM
analyzed
Sep 14, 2026, 02:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.