LWA-2026-12230 MAL-2026-16399 ↗ confirmed malware

lufxchwmxwyps@1.0.0

Malicious code in lufxchwmxwyps (npm)

T1566 · PhishingT1071 · Application Layer Protocol

Analysis

The package ships a single static HTML page that impersonates a Cloudflare "Just a moment..." Turnstile verification page. The page's inline JavaScript is obfuscated (encoded string array with a custom base64 decoder, an embedded AES key and host key) and renders a fake Turnstile challenge widget. When the visitor completes the challenge, the script invokes a redirect callback that sends them to an attacker-controlled destination. The page is a phishing-kit component intended to be served to victims to harvest credentials after a fake bot-check; the redirect target is obfuscated inside the script. The package has no install-time lifecycle scripts.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 08:50 AM
analyzed
Sep 18, 2026, 08:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.