lufxchwmxwyps@1.0.0
Malicious code in lufxchwmxwyps (npm)
Analysis
The package ships a single static HTML page that impersonates a Cloudflare "Just a moment..." Turnstile verification page. The page's inline JavaScript is obfuscated (encoded string array with a custom base64 decoder, an embedded AES key and host key) and renders a fake Turnstile challenge widget. When the visitor completes the challenge, the script invokes a redirect callback that sends them to an attacker-controlled destination. The page is a phishing-kit component intended to be served to victims to harvest credentials after a fake bot-check; the redirect target is obfuscated inside the script. The package has no install-time lifecycle scripts.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:50 AM
- analyzed
- Sep 18, 2026, 08:51 AM
Related advisories
- @worrisome/aaaa@1.0.0
- tib2jcvowuyma@1.0.0
- tibcwmpoeafh@1.0.0
- caphsmgiwy@1.0.0
- tuxcmdfhjkw@1.0.0
- dzcvhfruwluwe@1.0.0
- nhdxzthponv5@1.0.0
- operni@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.