Malicious code in fghvbmniwu (npm)
The npm package 'fghvbmniwu' versions 1.0.0 and 1.0.1 contains malicious code that serves a heavily obfuscated HTML page embedding a Cloudflare-branded Turnstile widget. This page redirects browsers to a constructed URL at runtime, indicating abuse of the npm registry as a free CDN for phishing or redirect landing pages. The malicious behavior only affects browsers loading the file via CDN mirrors and does not execute code during package installation or require/import in Node.js environments. Despite this, a security source warns that any system with this package installed or running should be considered fully compromised, recommending immediate secret/key rotation and package removal, though removal may not fully eliminate the threat. No official patch or fix is documented.
AI Analysis
Technical Summary
The 'fghvbmniwu' npm package (versions 1.0.0 and 1.0.1) contains a single 'index.html' file declared as the main entry point, which is a Cloudflare-branded 'Just a moment...' clone embedding a Turnstile widget. The JavaScript is heavily obfuscated using techniques such as control-flow flattening and shuffled string arrays, assembling a redirect URL at runtime and forwarding the current query string to it. There are no lifecycle scripts that execute code on installation or require/import, so the malicious payload only activates when the HTML file is loaded in a browser via CDN mirrors like unpkg or jsdelivr. This indicates the package is abused as a phishing or redirect landing page hosted on the npm registry rather than a direct installer attack. However, a security advisory states that any computer with this package installed or running should be treated as fully compromised, with immediate rotation of all secrets and keys recommended. Removal of the package is advised but may not fully remove all malicious software resulting from installation.
Potential Impact
The package does not execute malicious code during installation or runtime in Node.js environments, limiting direct impact on developer machines or build systems. However, when the package's main HTML file is loaded in a browser via CDN mirrors, it redirects users to potentially malicious URLs, facilitating phishing or other web-based attacks. The advisory warns that any system with this package installed or running should be considered fully compromised, implying potential backdoors or additional malicious payloads may exist beyond the described redirect behavior. This could lead to unauthorized access, data compromise, and credential theft if secrets or keys are stored on the affected system.
Mitigation Recommendations
No official patch or fix is documented for this package. Immediate removal of the 'fghvbmniwu' package versions 1.0.0 and 1.0.1 from all systems is recommended. All secrets and keys stored on affected systems should be rotated immediately from a separate, trusted computer. Because the advisory indicates full compromise is possible, further forensic investigation and remediation may be necessary. Monitor for any unusual activity and consider rebuilding affected systems if compromise is suspected. Since the malicious behavior activates only when the HTML file is loaded via CDN mirrors, avoid loading this package's content from untrusted sources.
Malicious code in fghvbmniwu (npm)
Description
The npm package 'fghvbmniwu' versions 1.0.0 and 1.0.1 contains malicious code that serves a heavily obfuscated HTML page embedding a Cloudflare-branded Turnstile widget. This page redirects browsers to a constructed URL at runtime, indicating abuse of the npm registry as a free CDN for phishing or redirect landing pages. The malicious behavior only affects browsers loading the file via CDN mirrors and does not execute code during package installation or require/import in Node.js environments. Despite this, a security source warns that any system with this package installed or running should be considered fully compromised, recommending immediate secret/key rotation and package removal, though removal may not fully eliminate the threat. No official patch or fix is documented.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'fghvbmniwu' npm package (versions 1.0.0 and 1.0.1) contains a single 'index.html' file declared as the main entry point, which is a Cloudflare-branded 'Just a moment...' clone embedding a Turnstile widget. The JavaScript is heavily obfuscated using techniques such as control-flow flattening and shuffled string arrays, assembling a redirect URL at runtime and forwarding the current query string to it. There are no lifecycle scripts that execute code on installation or require/import, so the malicious payload only activates when the HTML file is loaded in a browser via CDN mirrors like unpkg or jsdelivr. This indicates the package is abused as a phishing or redirect landing page hosted on the npm registry rather than a direct installer attack. However, a security advisory states that any computer with this package installed or running should be treated as fully compromised, with immediate rotation of all secrets and keys recommended. Removal of the package is advised but may not fully remove all malicious software resulting from installation.
Potential Impact
The package does not execute malicious code during installation or runtime in Node.js environments, limiting direct impact on developer machines or build systems. However, when the package's main HTML file is loaded in a browser via CDN mirrors, it redirects users to potentially malicious URLs, facilitating phishing or other web-based attacks. The advisory warns that any system with this package installed or running should be considered fully compromised, implying potential backdoors or additional malicious payloads may exist beyond the described redirect behavior. This could lead to unauthorized access, data compromise, and credential theft if secrets or keys are stored on the affected system.
Mitigation Recommendations
No official patch or fix is documented for this package. Immediate removal of the 'fghvbmniwu' package versions 1.0.0 and 1.0.1 from all systems is recommended. All secrets and keys stored on affected systems should be rotated immediately from a separate, trusted computer. Because the advisory indicates full compromise is possible, further forensic investigation and remediation may be necessary. Monitor for any unusual activity and consider rebuilding affected systems if compromise is suspected. Since the malicious behavior activates only when the HTML file is loaded via CDN mirrors, avoid loading this package's content from untrusted sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13808
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-52gv-9g4f-9j62"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b46bf8831d539cdd15b
Added to database: 08/12/2026, 16:11:50 UTC
Last enriched: 08/12/2026, 16:47:26 UTC
Last updated: 08/12/2026, 16:47:26 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.