fdhcxvnwhjiofv@1.0.0
Malicious code in fdhcxvnwhjiofv (npm)
T1189 · Drive-by CompromiseT1059.007 · JavaScriptT1552.001 · Credentials In Files
Analysis
The package ships a single obfuscated index.html that impersonates a Cloudflare Turnstile "Just a moment..." challenge page. The inline script is obfuscated with a base64 string-array and custom decoder, and embeds AES key material, a Turnstile site key, and a base64-decoding helper. It renders a cloned Cloudflare challenge layout and wires the Turnstile completion callback to a redirect handler, forming a phishing kit designed to harvest Turnstile tokens and redirect visitors. The page is served to victims rather than executed at install (no lifecycle hook).
- analyzed by
- Leitwacht
- first seen
- Sep 20, 2026, 03:25 AM
- analyzed
- Sep 20, 2026, 03:26 AM
Related advisories
- dzcvhfruwluwe@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- ndmckauxuoincv@1.0.0
- siriusbeyond@1.0.0
- chai-as-viem@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.