LWA-2026-12295 MAL-2026-16400 ↗ confirmed malware

ndmcjcxiebysfdb@1.0.0

Malicious code in ndmcjcxiebysfdb (npm)

T1566.002 · Spearphishing LinkT1027 · Obfuscated Files or Information

Analysis

The package ships a single obfuscated HTML page (index.html) that impersonates a Cloudflare Turnstile "please wait / security verification" challenge. The page loads the real Turnstile widget and embeds an AES key, a host key, and a Turnstile site key; once a visitor completes the challenge, the script redirects them to a phishing destination derived from those keys. It is a credential-harvesting phishing page distributed as an npm package.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 08:23 AM
analyzed
Sep 21, 2026, 08:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.