LWA-2026-12273 MAL-2026-16402 ↗ confirmed malware

ndmcmsujey@1.0.0

Malicious code in ndmcmsujey (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This npm package ships a single static HTML file that reproduces a Cloudflare "Just a moment..." Turnstile challenge page. The embedded JavaScript is heavily obfuscated with an encoded string array and a custom decoder. The package declares no lifecycle scripts and no executable entry points, so it performs no action at install time; as a browser-facing page it renders a Turnstile challenge widget. No credential submission, cookie access, or outbound data transfer beyond the Cloudflare Turnstile endpoint was identified in the shipped code.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 06:58 AM
analyzed
Sep 20, 2026, 06:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.