ndmckauxuoincv@1.0.0
Malicious code in ndmckauxuoincv (npm)
Analysis
The package ships a single obfuscated HTML page disguised as a Cloudflare Turnstile "challenge" page (Traditional Chinese). When a victim is redirected to it, the page presents a fake Cloudflare verification widget while its obfuscated JavaScript reads the victim's URL query string (which commonly carries auth codes and session tokens) and exfiltrates those parameters to an attacker-controlled endpoint, encrypting the harvested data with AES using a hardcoded key. The page also decodes an embedded base64 payload. This is a credential/session-harvesting phishing kit: the URL parameters are collected and sent off-host.
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 09:18 AM
- analyzed
- Sep 21, 2026, 09:19 AM
Related advisories
- fdhcxvnwhjiofv@1.0.0
- dzcvhfruwluwe@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- npmscript_tesstalert_unpkg@1.0.1
- my-ctf-helper-script-9921@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.