Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in bcnfjndwbkf2 (npm)

0
Medium
Published: 08/12/2026 (08/12/2026, 10:29:52 UTC)
Source: GCVE Database
Product: bcnfjndwbkf2

Description

The npm package 'bcnfjndwbkf2' version 1.0.0 contains malicious code that serves an obfuscated HTML redirect page mimicking a Cloudflare interstitial. This package does not execute code during installation or runtime in Node.js environments but redirects browser visitors who access the package via npm CDN mirrors to a potentially malicious URL. Although it does not represent a traditional supply-chain attack via npm install, the package abuses npm as a static host for browser-side redirection. One source claims that any system with this package installed or running should be considered fully compromised, recommending immediate secret rotation and package removal.

Affected software

npmghsa
bcnfjndwbkf2
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:54:14 UTC

Technical Analysis

The 'bcnfjndwbkf2' npm package version 1.0.0 contains only an index.html file that mimics a Cloudflare 'Just a moment...' page and, after a short delay, runs obfuscated JavaScript to redirect browser visitors to a constructed target URL. Because the package's main entry is an HTML file with no scripts or binaries, it cannot be required or imported in Node.js, nor does it execute code on npm install. The malicious behavior only manifests when the HTML is fetched and rendered in a browser via npm CDN mirrors like unpkg or jsdelivr. This is an abuse of npm's static hosting capabilities rather than a direct supply-chain compromise. However, a secondary source claims that any computer with this package installed or running should be considered fully compromised, advising immediate secret rotation and removal, though this claim is not supported by the technical details.

Potential Impact

The package does not execute code during installation or runtime in Node.js environments, so it does not directly compromise systems through typical npm supply-chain vectors. The malicious redirect affects only browser visitors who load the package's HTML via npm CDN mirrors, potentially leading users to malicious sites. The claim that any system with this package installed is fully compromised is not corroborated by the technical analysis, which shows no lifecycle hooks or executable code in the package itself. Therefore, the direct impact is limited to browser-based redirection rather than system compromise via npm install.

Mitigation Recommendations

Since the package does not execute code during installation or runtime, the primary mitigation is to avoid using or serving this package via npm CDN mirrors to browsers. Removing the package from projects and blocking access to its CDN URLs can prevent browser-based redirects. The claim that systems with this package installed are fully compromised is not supported by the technical details; however, if the package was installed, removing it is recommended. No official patch or fix is applicable as this is a malicious package abuse rather than a vulnerability in legitimate software.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13783
Osv Schema Version
1.7.4
Aliases
["GHSA-7cv8-7v66-c3mh"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b46bf8831d539cdd284

Added to database: 08/12/2026, 16:11:50 UTC

Last enriched: 08/12/2026, 16:54:14 UTC

Last updated: 08/12/2026, 16:54:14 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses