Malicious code in bcnfjndwbkf2 (npm)
The npm package 'bcnfjndwbkf2' version 1.0.0 contains malicious code that serves an obfuscated HTML redirect page mimicking a Cloudflare interstitial. This package does not execute code during installation or runtime in Node.js environments but redirects browser visitors who access the package via npm CDN mirrors to a potentially malicious URL. Although it does not represent a traditional supply-chain attack via npm install, the package abuses npm as a static host for browser-side redirection. One source claims that any system with this package installed or running should be considered fully compromised, recommending immediate secret rotation and package removal.
AI Analysis
Technical Summary
The 'bcnfjndwbkf2' npm package version 1.0.0 contains only an index.html file that mimics a Cloudflare 'Just a moment...' page and, after a short delay, runs obfuscated JavaScript to redirect browser visitors to a constructed target URL. Because the package's main entry is an HTML file with no scripts or binaries, it cannot be required or imported in Node.js, nor does it execute code on npm install. The malicious behavior only manifests when the HTML is fetched and rendered in a browser via npm CDN mirrors like unpkg or jsdelivr. This is an abuse of npm's static hosting capabilities rather than a direct supply-chain compromise. However, a secondary source claims that any computer with this package installed or running should be considered fully compromised, advising immediate secret rotation and removal, though this claim is not supported by the technical details.
Potential Impact
The package does not execute code during installation or runtime in Node.js environments, so it does not directly compromise systems through typical npm supply-chain vectors. The malicious redirect affects only browser visitors who load the package's HTML via npm CDN mirrors, potentially leading users to malicious sites. The claim that any system with this package installed is fully compromised is not corroborated by the technical analysis, which shows no lifecycle hooks or executable code in the package itself. Therefore, the direct impact is limited to browser-based redirection rather than system compromise via npm install.
Mitigation Recommendations
Since the package does not execute code during installation or runtime, the primary mitigation is to avoid using or serving this package via npm CDN mirrors to browsers. Removing the package from projects and blocking access to its CDN URLs can prevent browser-based redirects. The claim that systems with this package installed are fully compromised is not supported by the technical details; however, if the package was installed, removing it is recommended. No official patch or fix is applicable as this is a malicious package abuse rather than a vulnerability in legitimate software.
Malicious code in bcnfjndwbkf2 (npm)
Description
The npm package 'bcnfjndwbkf2' version 1.0.0 contains malicious code that serves an obfuscated HTML redirect page mimicking a Cloudflare interstitial. This package does not execute code during installation or runtime in Node.js environments but redirects browser visitors who access the package via npm CDN mirrors to a potentially malicious URL. Although it does not represent a traditional supply-chain attack via npm install, the package abuses npm as a static host for browser-side redirection. One source claims that any system with this package installed or running should be considered fully compromised, recommending immediate secret rotation and package removal.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'bcnfjndwbkf2' npm package version 1.0.0 contains only an index.html file that mimics a Cloudflare 'Just a moment...' page and, after a short delay, runs obfuscated JavaScript to redirect browser visitors to a constructed target URL. Because the package's main entry is an HTML file with no scripts or binaries, it cannot be required or imported in Node.js, nor does it execute code on npm install. The malicious behavior only manifests when the HTML is fetched and rendered in a browser via npm CDN mirrors like unpkg or jsdelivr. This is an abuse of npm's static hosting capabilities rather than a direct supply-chain compromise. However, a secondary source claims that any computer with this package installed or running should be considered fully compromised, advising immediate secret rotation and removal, though this claim is not supported by the technical details.
Potential Impact
The package does not execute code during installation or runtime in Node.js environments, so it does not directly compromise systems through typical npm supply-chain vectors. The malicious redirect affects only browser visitors who load the package's HTML via npm CDN mirrors, potentially leading users to malicious sites. The claim that any system with this package installed is fully compromised is not corroborated by the technical analysis, which shows no lifecycle hooks or executable code in the package itself. Therefore, the direct impact is limited to browser-based redirection rather than system compromise via npm install.
Mitigation Recommendations
Since the package does not execute code during installation or runtime, the primary mitigation is to avoid using or serving this package via npm CDN mirrors to browsers. Removing the package from projects and blocking access to its CDN URLs can prevent browser-based redirects. The claim that systems with this package installed are fully compromised is not supported by the technical details; however, if the package was installed, removing it is recommended. No official patch or fix is applicable as this is a malicious package abuse rather than a vulnerability in legitimate software.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13783
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-7cv8-7v66-c3mh"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b46bf8831d539cdd284
Added to database: 08/12/2026, 16:11:50 UTC
Last enriched: 08/12/2026, 16:54:14 UTC
Last updated: 08/12/2026, 16:54:14 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.