Malicious code in dzcvhfruwluwe (npm)
The npm package 'dzcvhfruwluwe' versions 1.0.0 and 1.0.1 contains a malicious index.html file that acts as a fake 'Cloudflare Verifying...' page. This page uses obfuscated JavaScript to redirect users' browsers after a short delay to an attacker-controlled external domain. The malicious behavior is client-side and does not execute during package installation or require-time, meaning it does not compromise the developer's environment directly. However, end users who load the HTML file in a browser are redirected to potentially harmful sites. This is a case of registry abuse hosting phishing or malvertising content rather than a traditional supply-chain attack. There is no CVSS score available for this threat. The package should be removed, and any secrets on compromised machines should be rotated due to the risk of full compromise.
AI Analysis
Technical Summary
The npm package 'dzcvhfruwluwe' (versions 1.0.0 and 1.0.1) contains a single file, index.html, which displays a fake 'Cloudflare Verifying...' page. This page includes an obfuscated script that reconstructs a URL to an attacker-controlled domain and redirects the browser to that domain after a 1-second timeout using window.location.replace. The package.json does not define lifecycle scripts and points the main entry to the HTML file, so the malicious payload does not execute during npm install or require(). The threat is limited to browser-side redirection for users who load the HTML file, representing registry abuse for phishing or malvertising purposes rather than a supply-chain compromise of the developer environment. The advisory from ghsa-malware warns that any computer with this package installed or running should be considered fully compromised, recommending immediate secret/key rotation and package removal, though removal may not eliminate all malicious software.
Potential Impact
End users who load the malicious index.html file in a browser are redirected to an attacker-controlled domain, potentially exposing them to phishing or malvertising content. The package does not execute malicious code during installation or runtime in the developer environment, so the direct impact on developers is limited. However, the ghsa-malware advisory states that any computer with this package installed or running should be considered fully compromised, implying that the package may be part of a broader compromise or that additional malicious components may be present. Secrets and keys on affected machines should be rotated immediately. There is no evidence of active exploitation in the wild.
Mitigation Recommendations
Remove the 'dzcvhfruwluwe' package from all affected systems. Immediately rotate all secrets and keys stored on any computer where this package was installed or running, using a different, uncompromised machine. Since the malicious payload is browser-side and the package does not execute during installation, ensure users do not open the index.html file from this package. Monitor for any further signs of compromise as removal of the package alone may not eliminate all malicious software. Patch status is not yet confirmed — check vendor advisories for any updates or official fixes.
Malicious code in dzcvhfruwluwe (npm)
Description
The npm package 'dzcvhfruwluwe' versions 1.0.0 and 1.0.1 contains a malicious index.html file that acts as a fake 'Cloudflare Verifying...' page. This page uses obfuscated JavaScript to redirect users' browsers after a short delay to an attacker-controlled external domain. The malicious behavior is client-side and does not execute during package installation or require-time, meaning it does not compromise the developer's environment directly. However, end users who load the HTML file in a browser are redirected to potentially harmful sites. This is a case of registry abuse hosting phishing or malvertising content rather than a traditional supply-chain attack. There is no CVSS score available for this threat. The package should be removed, and any secrets on compromised machines should be rotated due to the risk of full compromise.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package 'dzcvhfruwluwe' (versions 1.0.0 and 1.0.1) contains a single file, index.html, which displays a fake 'Cloudflare Verifying...' page. This page includes an obfuscated script that reconstructs a URL to an attacker-controlled domain and redirects the browser to that domain after a 1-second timeout using window.location.replace. The package.json does not define lifecycle scripts and points the main entry to the HTML file, so the malicious payload does not execute during npm install or require(). The threat is limited to browser-side redirection for users who load the HTML file, representing registry abuse for phishing or malvertising purposes rather than a supply-chain compromise of the developer environment. The advisory from ghsa-malware warns that any computer with this package installed or running should be considered fully compromised, recommending immediate secret/key rotation and package removal, though removal may not eliminate all malicious software.
Potential Impact
End users who load the malicious index.html file in a browser are redirected to an attacker-controlled domain, potentially exposing them to phishing or malvertising content. The package does not execute malicious code during installation or runtime in the developer environment, so the direct impact on developers is limited. However, the ghsa-malware advisory states that any computer with this package installed or running should be considered fully compromised, implying that the package may be part of a broader compromise or that additional malicious components may be present. Secrets and keys on affected machines should be rotated immediately. There is no evidence of active exploitation in the wild.
Mitigation Recommendations
Remove the 'dzcvhfruwluwe' package from all affected systems. Immediately rotate all secrets and keys stored on any computer where this package was installed or running, using a different, uncompromised machine. Since the malicious payload is browser-side and the package does not execute during installation, ensure users do not open the index.html file from this package. Monitor for any further signs of compromise as removal of the package alone may not eliminate all malicious software. Patch status is not yet confirmed — check vendor advisories for any updates or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13803
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-vfhv-rjx5-6c95"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b4dbf8831d539cdd750
Added to database: 08/12/2026, 16:11:57 UTC
Last enriched: 08/12/2026, 16:59:37 UTC
Last updated: 08/13/2026, 01:39:37 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.