Malicious code in china_airlines (npm)
The npm package 'china_airlines' version 1.0.0 contains no legitimate JavaScript library code but instead hosts a heavily obfuscated phishing landing page disguised as a Cloudflare interstitial. It uses obfuscated JavaScript to redirect users visiting the package via public CDN mirrors to a malicious target URL, abusing npm and CDN infrastructure for phishing. The package itself does not execute malicious code during installation or import, so it does not directly compromise developer machines through install-time code execution. However, browsers visiting the hosted page can be redirected to phishing sites. According to one source, any computer with this package installed should be considered fully compromised, though this claim conflicts with the inert install surface described. No official patch or remediation is documented.
AI Analysis
Technical Summary
The 'china_airlines' npm package version 1.0.0 contains no functional library code but instead serves a fake Cloudflare 'Just a moment...' page with a fake Turnstile widget. The page's JavaScript is heavily obfuscated and decodes a hidden target URL to which it redirects users, forwarding query parameters. This behavior is designed to abuse npm and public CDN mirrors (unpkg, jsDelivr) as free hosting for a phishing landing page impersonating a brand. The package does not execute code on install or import, so it does not perform installer-side exfiltration, remote code execution, or credential theft. The threat targets browser users who visit the CDN-hosted page rather than developers installing the package. One source claims full compromise of machines with the package installed, but the technical analysis indicates the malicious payload is only active in the browser context when accessing the hosted HTML page.
Potential Impact
Users who visit the package's hosted HTML page via public CDN links may be redirected to phishing sites, potentially exposing them to credential theft or other phishing attacks. Developers installing or requiring the package do not face direct code execution or credential theft risks from the package itself. The package abuses npm and CDN infrastructure to host phishing content, potentially damaging brand reputation and user trust. There is no evidence of direct compromise of developer machines through installation or runtime code execution. The claim that any computer with this package installed is fully compromised is not supported by the technical details describing an inert install surface.
Mitigation Recommendations
No official patch or remediation is documented. Since the malicious behavior occurs only when visiting the hosted HTML page via CDN links, users and organizations should avoid accessing this package's files through public CDN URLs. Developers should avoid installing or using the 'china_airlines' package version 1.0.0. Removal of the package from development environments is recommended. Rotate any secrets or keys if the package was installed, as a precaution, although direct compromise via installation is not indicated. Monitor for and block access to known malicious CDN URLs hosting this package's content. Check vendor advisories or npm security advisories for updates or takedown notices regarding this package.
Malicious code in china_airlines (npm)
Description
The npm package 'china_airlines' version 1.0.0 contains no legitimate JavaScript library code but instead hosts a heavily obfuscated phishing landing page disguised as a Cloudflare interstitial. It uses obfuscated JavaScript to redirect users visiting the package via public CDN mirrors to a malicious target URL, abusing npm and CDN infrastructure for phishing. The package itself does not execute malicious code during installation or import, so it does not directly compromise developer machines through install-time code execution. However, browsers visiting the hosted page can be redirected to phishing sites. According to one source, any computer with this package installed should be considered fully compromised, though this claim conflicts with the inert install surface described. No official patch or remediation is documented.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'china_airlines' npm package version 1.0.0 contains no functional library code but instead serves a fake Cloudflare 'Just a moment...' page with a fake Turnstile widget. The page's JavaScript is heavily obfuscated and decodes a hidden target URL to which it redirects users, forwarding query parameters. This behavior is designed to abuse npm and public CDN mirrors (unpkg, jsDelivr) as free hosting for a phishing landing page impersonating a brand. The package does not execute code on install or import, so it does not perform installer-side exfiltration, remote code execution, or credential theft. The threat targets browser users who visit the CDN-hosted page rather than developers installing the package. One source claims full compromise of machines with the package installed, but the technical analysis indicates the malicious payload is only active in the browser context when accessing the hosted HTML page.
Potential Impact
Users who visit the package's hosted HTML page via public CDN links may be redirected to phishing sites, potentially exposing them to credential theft or other phishing attacks. Developers installing or requiring the package do not face direct code execution or credential theft risks from the package itself. The package abuses npm and CDN infrastructure to host phishing content, potentially damaging brand reputation and user trust. There is no evidence of direct compromise of developer machines through installation or runtime code execution. The claim that any computer with this package installed is fully compromised is not supported by the technical details describing an inert install surface.
Mitigation Recommendations
No official patch or remediation is documented. Since the malicious behavior occurs only when visiting the hosted HTML page via CDN links, users and organizations should avoid accessing this package's files through public CDN URLs. Developers should avoid installing or using the 'china_airlines' package version 1.0.0. Removal of the package from development environments is recommended. Rotate any secrets or keys if the package was installed, as a precaution, although direct compromise via installation is not indicated. Monitor for and block access to known malicious CDN URLs hosting this package's content. Check vendor advisories or npm security advisories for updates or takedown notices regarding this package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13791
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-6gv6-cwww-6793"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b46bf8831d539cdd1f3
Added to database: 08/12/2026, 16:11:50 UTC
Last enriched: 08/12/2026, 16:51:17 UTC
Last updated: 08/13/2026, 01:39:36 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.