luftmvfiwgxydes@1.0.0
Malicious code in luftmvfiwgxydes (npm)
Analysis
The package ships a single heavily-obfuscated HTML file that impersonates a Cloudflare "Just a moment..." Turnstile challenge page. The page is a phishing kit: its obfuscated JavaScript builds a fake Turnstile challenge, embeds AES-key and host-key constants, decodes base64 payloads, and reads and forwards URL query parameters (visitor params). It is designed to be served to victims to run them through a fake challenge flow and harvest credentials. The package has no install scripts and no dependencies; the malicious artifact is the bundled phishing page itself.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 02:22 AM
- analyzed
- Sep 18, 2026, 02:23 AM
Related advisories
- luftzxyuiwgbgsp@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- cloudndmcedu@1.0.0
- ndmcjcxiebysfdb@1.0.0
- chai-as-indexed@7.2.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.