LWA-2026-5293 confirmed malware

thienc-cdn@1.0.0

Malicious code in thienc-cdn (npm)

T1195.002 · Compromise Software Supply ChainT1185 · Browser Session HijackingT1505.003 · Disable or Modify ToolsT1102 · Web Service

Analysis

A malicious package masquerading as a CDN that hijacks the browser page at runtime. On load, main.js injects a remote script from node12[.]aizhantj[.]com:21233/tjjs/?k=18k6tpxdnsx and inserts a full-viewport iframe (z-index 9999, overflow hidden) served from a daily-rotating subdomain on 182[.]run (e.g. 1506[.]182[.]run). The package also blocks F12 devtools, right-click context menu, and text selection to hinder inspection. It provides no actual CDN functionality.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 03:02 AM
analyzed
Jun 15, 2026, 03:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.