Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in csbcldfvivwfgd4 (npm)

0
Medium
Published: 08/12/2026 (08/12/2026, 10:29:52 UTC)
Source: GCVE Database
Product: csbcldfvivwfgd4

Description

The npm package csbcldfvivwfgd4 version 1.0.0 contains a malicious index.html file that mimics a Cloudflare challenge page and includes obfuscated JavaScript which redirects browser users to a potentially harmful URL. This malicious behavior only triggers when the HTML is rendered in a browser via an npm-backed CDN, not during installation or import in a Node.js environment. There is no code execution or credential theft on the installer's machine, but the package is abused as a phishing or malvertising redirect hosted on the npm registry.

Affected software

npmghsa
csbcldfvivwfgd4
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:50:17 UTC

Technical Analysis

The csbcldfvivwfgd4 npm package (version 1.0.0) includes a single index.html file declared as the main entry point. This HTML file contains obfuscated JavaScript that constructs a redirect URL and forces a browser redirect when fetched and rendered via npm-backed CDNs such as unpkg or jsdelivr. Because the main file is HTML and not executable JavaScript, requiring or installing the package in Node.js environments does not execute any malicious code. The threat arises from the package being used as a hosting mechanism for phishing or malvertising redirects targeting browser end-users who access the package content through CDN URLs. The package does not perform any harmful actions on the installer's machine, such as exfiltration or persistence. However, a conflicting source claims that any system with this package installed should be considered fully compromised, recommending secret rotation and package removal, though this is inconsistent with the installer-centric threat model described.

Potential Impact

The malicious package does not execute harmful code during installation or import in Node.js environments, so developers installing or requiring it are not directly compromised. The impact is on browser users who access the package's HTML via npm-backed CDNs, where the obfuscated JavaScript redirects them to potentially malicious sites, enabling phishing or malvertising attacks. There is no evidence of direct code execution, credential theft, or persistence on the installer's machine. The conflicting claim that systems with the package installed are fully compromised is not supported by the technical details describing the attack vector as browser-based only.

Mitigation Recommendations

Since the malicious behavior only occurs when the package's HTML is rendered in a browser via npm-backed CDNs, developers installing or requiring the package in Node.js environments are not at risk. Users should avoid accessing this package via CDN URLs in browsers. The package version 1.0.0 should be removed from projects if present. There is no official patch or fix available. Secret rotation is recommended only if there is evidence of compromise beyond the described browser redirect behavior, but this is not confirmed by the vendor advisory. Monitor for and block access to the package's CDN URLs to prevent browser-based exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13795
Osv Schema Version
1.7.4
Aliases
["GHSA-5pjw-x44v-j286"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b46bf8831d539cdd1e3

Added to database: 08/12/2026, 16:11:50 UTC

Last enriched: 08/12/2026, 16:50:17 UTC

Last updated: 08/13/2026, 01:39:44 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses