LWA-2026-12313 MAL-2026-16391 ↗ confirmed malware

cloudndmcedu@1.0.0

Malicious code in cloudndmcedu (npm)

T1566.002 · Spearphishing LinkT1041 · Exfiltration Over C2 ChannelT1573 · Encrypted Channel

Analysis

cloudndmcedu@1.0.0 ships a single obfuscated index.html that impersonates a Cloudflare Turnstile CAPTCHA challenge page. Its JavaScript reads the current page URL's query parameters, appends them to an attacker-controlled destination URL, and redirects the visitor there after the fake challenge completes, using AES encryption with a hardcoded key to protect the collected parameters. This is a credential-harvesting phishing page designed to capture tokens/credentials passed in the URL and forward them to the attacker.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 03:25 AM
analyzed
Sep 22, 2026, 03:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.