redirect-azlazy@1.0.0
Malicious code in redirect-azlazy (npm)
Analysis
Package redirect-azlazy@1.0.0 ships a main module (beamglea.js) that performs a hardcoded browser redirect to cfn[.]kafiky[.]com/NPiGdCBx#[account] via window.location.href. It also includes a templated variant (beamglea_template.js) with {{EMAIL}} and {{URL}} placeholders, indicating this is a bulk-generated redirect package from a campaign producing many npm packages with different redirect targets. The code does nothing in a Node.js runtime (no lifecycle hooks, no child_process, no file access), but when loaded in a browser or bundler context it silently redirects users to an external domain with an email address appended as a fragment identifier. The destination domain cfn[.]kafiky[.]com is not a known legitimate service.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 03:08 AM
- analyzed
- Jun 13, 2026, 03:08 AM
Related advisories
- oit-lib-oracle-util@45.0.0
- no-date-parsing@2.2.0
- firefly-utilities-helper@99.9.1
- optional-cpu-features@1.0.3
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.