LWA-2026-12297 MAL-2026-16401 ↗ confirmed malware

ndmckauxuoincv@1.0.0

Malicious code in ndmckauxuoincv (npm)

T1189 · Drive-by CompromiseT1539 · Steal Web Session CookieT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 Channel

Analysis

The package ships a single obfuscated HTML page disguised as a Cloudflare Turnstile "challenge" page (Traditional Chinese). When a victim is redirected to it, the page presents a fake Cloudflare verification widget while its obfuscated JavaScript reads the victim's URL query string (which commonly carries auth codes and session tokens) and exfiltrates those parameters to an attacker-controlled endpoint, encrypting the harvested data with AES using a hardcoded key. The page also decodes an embedded base64 payload. This is a credential/session-harvesting phishing kit: the URL parameters are collected and sent off-host.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 09:18 AM
analyzed
Sep 21, 2026, 09:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.