cloudndmcedu@1.0.0
Malicious code in cloudndmcedu (npm)
T1566.002 · Spearphishing LinkT1041 · Exfiltration Over C2 ChannelT1573 · Encrypted Channel
Analysis
cloudndmcedu@1.0.0 ships a single obfuscated index.html that impersonates a Cloudflare Turnstile CAPTCHA challenge page. Its JavaScript reads the current page URL's query parameters, appends them to an attacker-controlled destination URL, and redirects the visitor there after the fake challenge completes, using AES encryption with a hardcoded key to protect the collected parameters. This is a credential-harvesting phishing page designed to capture tokens/credentials passed in the URL and forward them to the attacker.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 03:25 AM
- analyzed
- Sep 22, 2026, 03:28 AM
Related advisories
- ndmcjcxiebysfdb@1.0.0
- luftmvfiwgxydes@1.0.0
- luftzxyuiwgbgsp@1.0.0
- twcvhjlksdmx@1.0.0
- passport811@1.0.0
- mnteckets@1.0.1
- ms_aidc_com_tw@1.0.0
- ndmckauxuoincv@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.