Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in china_airlines (npm)

0
High
Published: 08/12/2026 (08/12/2026, 10:29:51 UTC)
Source: GCVE Database
Product: china_airlines

Description

The npm package 'china_airlines' version 1.0.0 contains no legitimate JavaScript library code but instead hosts a heavily obfuscated phishing landing page disguised as a Cloudflare interstitial. It uses obfuscated JavaScript to redirect users visiting the package via public CDN mirrors to a malicious target URL, abusing npm and CDN infrastructure for phishing. The package itself does not execute malicious code during installation or import, so it does not directly compromise developer machines through install-time code execution. However, browsers visiting the hosted page can be redirected to phishing sites. According to one source, any computer with this package installed should be considered fully compromised, though this claim conflicts with the inert install surface described. No official patch or remediation is documented.

Affected software

npmghsa
china_airlines
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:51:17 UTC

Technical Analysis

The 'china_airlines' npm package version 1.0.0 contains no functional library code but instead serves a fake Cloudflare 'Just a moment...' page with a fake Turnstile widget. The page's JavaScript is heavily obfuscated and decodes a hidden target URL to which it redirects users, forwarding query parameters. This behavior is designed to abuse npm and public CDN mirrors (unpkg, jsDelivr) as free hosting for a phishing landing page impersonating a brand. The package does not execute code on install or import, so it does not perform installer-side exfiltration, remote code execution, or credential theft. The threat targets browser users who visit the CDN-hosted page rather than developers installing the package. One source claims full compromise of machines with the package installed, but the technical analysis indicates the malicious payload is only active in the browser context when accessing the hosted HTML page.

Potential Impact

Users who visit the package's hosted HTML page via public CDN links may be redirected to phishing sites, potentially exposing them to credential theft or other phishing attacks. Developers installing or requiring the package do not face direct code execution or credential theft risks from the package itself. The package abuses npm and CDN infrastructure to host phishing content, potentially damaging brand reputation and user trust. There is no evidence of direct compromise of developer machines through installation or runtime code execution. The claim that any computer with this package installed is fully compromised is not supported by the technical details describing an inert install surface.

Mitigation Recommendations

No official patch or remediation is documented. Since the malicious behavior occurs only when visiting the hosted HTML page via CDN links, users and organizations should avoid accessing this package's files through public CDN URLs. Developers should avoid installing or using the 'china_airlines' package version 1.0.0. Removal of the package from development environments is recommended. Rotate any secrets or keys if the package was installed, as a precaution, although direct compromise via installation is not indicated. Monitor for and block access to known malicious CDN URLs hosting this package's content. Check vendor advisories or npm security advisories for updates or takedown notices regarding this package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13791
Osv Schema Version
1.7.4
Aliases
["GHSA-6gv6-cwww-6793"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b46bf8831d539cdd1f3

Added to database: 08/12/2026, 16:11:50 UTC

Last enriched: 08/12/2026, 16:51:17 UTC

Last updated: 08/13/2026, 01:39:36 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses