Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in fghvbmniwu (npm)

0
High
Published: 08/12/2026 (08/12/2026, 10:29:53 UTC)
Source: GCVE Database
Product: fghvbmniwu

Description

The npm package 'fghvbmniwu' versions 1.0.0 and 1.0.1 contains malicious code that serves a heavily obfuscated HTML page embedding a Cloudflare-branded Turnstile widget. This page redirects browsers to a constructed URL at runtime, indicating abuse of the npm registry as a free CDN for phishing or redirect landing pages. The malicious behavior only affects browsers loading the file via CDN mirrors and does not execute code during package installation or require/import in Node.js environments. Despite this, a security source warns that any system with this package installed or running should be considered fully compromised, recommending immediate secret/key rotation and package removal, though removal may not fully eliminate the threat. No official patch or fix is documented.

Affected software

npmghsa
fghvbmniwu
Affected versions
=1.0.1=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:47:26 UTC

Technical Analysis

The 'fghvbmniwu' npm package (versions 1.0.0 and 1.0.1) contains a single 'index.html' file declared as the main entry point, which is a Cloudflare-branded 'Just a moment...' clone embedding a Turnstile widget. The JavaScript is heavily obfuscated using techniques such as control-flow flattening and shuffled string arrays, assembling a redirect URL at runtime and forwarding the current query string to it. There are no lifecycle scripts that execute code on installation or require/import, so the malicious payload only activates when the HTML file is loaded in a browser via CDN mirrors like unpkg or jsdelivr. This indicates the package is abused as a phishing or redirect landing page hosted on the npm registry rather than a direct installer attack. However, a security advisory states that any computer with this package installed or running should be treated as fully compromised, with immediate rotation of all secrets and keys recommended. Removal of the package is advised but may not fully remove all malicious software resulting from installation.

Potential Impact

The package does not execute malicious code during installation or runtime in Node.js environments, limiting direct impact on developer machines or build systems. However, when the package's main HTML file is loaded in a browser via CDN mirrors, it redirects users to potentially malicious URLs, facilitating phishing or other web-based attacks. The advisory warns that any system with this package installed or running should be considered fully compromised, implying potential backdoors or additional malicious payloads may exist beyond the described redirect behavior. This could lead to unauthorized access, data compromise, and credential theft if secrets or keys are stored on the affected system.

Mitigation Recommendations

No official patch or fix is documented for this package. Immediate removal of the 'fghvbmniwu' package versions 1.0.0 and 1.0.1 from all systems is recommended. All secrets and keys stored on affected systems should be rotated immediately from a separate, trusted computer. Because the advisory indicates full compromise is possible, further forensic investigation and remediation may be necessary. Monitor for any unusual activity and consider rebuilding affected systems if compromise is suspected. Since the malicious behavior activates only when the HTML file is loaded via CDN mirrors, avoid loading this package's content from untrusted sources.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13808
Osv Schema Version
1.7.4
Aliases
["GHSA-52gv-9g4f-9j62"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b46bf8831d539cdd15b

Added to database: 08/12/2026, 16:11:50 UTC

Last enriched: 08/12/2026, 16:47:26 UTC

Last updated: 08/12/2026, 16:47:26 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses