ndmcmsujey@1.0.0
Malicious code in ndmcmsujey (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
This npm package ships a single static HTML file that reproduces a Cloudflare "Just a moment..." Turnstile challenge page. The embedded JavaScript is heavily obfuscated with an encoded string array and a custom decoder. The package declares no lifecycle scripts and no executable entry points, so it performs no action at install time; as a browser-facing page it renders a Turnstile challenge widget. No credential submission, cookie access, or outbound data transfer beyond the Cloudflare Turnstile endpoint was identified in the shipped code.
- analyzed by
- Leitwacht
- first seen
- Sep 20, 2026, 06:58 AM
- analyzed
- Sep 20, 2026, 06:59 AM
Related advisories
- starbucks-sdk@1.0.0
- chai-as-viem@1.1.3
- keroeltopkkk@99.99.99
- keroeltopkk@99.99.99
- keroeltop@99.99.99
- test1df23@99.99.99
- test1hh235@99.99.99
- melbet-cm@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.