ndmcjcxiebysfdb@1.0.0
Malicious code in ndmcjcxiebysfdb (npm)
T1566.002 · Spearphishing LinkT1027 · Obfuscated Files or Information
Analysis
The package ships a single obfuscated HTML page (index.html) that impersonates a Cloudflare Turnstile "please wait / security verification" challenge. The page loads the real Turnstile widget and embeds an AES key, a host key, and a Turnstile site key; once a visitor completes the challenge, the script redirects them to a phishing destination derived from those keys. It is a credential-harvesting phishing page distributed as an npm package.
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 08:23 AM
- analyzed
- Sep 21, 2026, 08:24 AM
Related advisories
- luftmvfiwgxydes@1.0.0
- luftzxyuiwgbgsp@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- cloudndmcedu@1.0.0
- testmgkregme@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.