LWA-2026-5293 confirmed malware
thienc-cdn@1.0.0
Malicious code in thienc-cdn (npm)
T1195.002 · Compromise Software Supply ChainT1185 · Browser Session HijackingT1505.003 · Disable or Modify ToolsT1102 · Web Service
Analysis
A malicious package masquerading as a CDN that hijacks the browser page at runtime. On load, main.js injects a remote script from node12[.]aizhantj[.]com:21233/tjjs/?k=18k6tpxdnsx and inserts a full-viewport iframe (z-index 9999, overflow hidden) served from a daily-rotating subdomain on 182[.]run (e.g. 1506[.]182[.]run). The package also blocks F12 devtools, right-click context menu, and text selection to hinder inspection. It provides no actual CDN functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 03:02 AM
- analyzed
- Jun 15, 2026, 03:03 AM
Related advisories
- system-drive@1.0.0
- sqrt-bn-enhanced@2.0.9
- snavbox@1.0.1
- seed-to-private@1.0.1
- rapidsearch@1.1.0
- protectstraizolib@1.0.8
- polymarket-onchain-plugin@2.1.3
- pino-pretty-logs@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.