Malicious code in jhkxcixudnvm1 (npm)
The npm package 'jhkxcixudnvm1' versions 1.0.0 and 1.0.1 contains a malicious HTML file that impersonates a Cloudflare verification page and redirects users to a potentially harmful destination URL. The package does not execute JavaScript during installation or when required in code, so it does not directly compromise build systems or installers. However, if the package contents are served and accessed via a browser (e.g., through a CDN), end-users could be redirected to phishing or malicious sites. The package represents registry abuse rather than a traditional supply-chain code execution vulnerability.
AI Analysis
Technical Summary
The 'jhkxcixudnvm1' npm package includes only a package.json and an index.html file declared as the main entry point. The index.html mimics a Cloudflare 'Just a moment...' interstitial page and contains obfuscated JavaScript that reconstructs and redirects to a destination URL after a short delay, forwarding query parameters. No JavaScript runs during npm install or when requiring the package, so the malicious behavior only manifests if the HTML is opened in a browser. This is a case of npm registry abuse hosting a phishing/redirect page, which could harm end-users if the package content is served via a web context. The package does not directly compromise the installer's environment or exfiltrate data during installation.
Potential Impact
End-users who access the package's index.html in a browser context (such as through a CDN serving package contents) may be redirected to a malicious site impersonating Cloudflare, potentially leading to phishing or other harm. There is no direct impact on systems that merely install or require the package in code, as no code execution or credential theft occurs during these operations. However, the presence of this package in an environment may indicate registry abuse and potential exposure to phishing attacks if the malicious HTML is served to users.
Mitigation Recommendations
Since the malicious behavior only occurs if the package's HTML content is served and accessed in a browser, remediation should focus on registry abuse takedown procedures rather than supply-chain blocking. Removing the package from the registry and preventing its distribution via CDNs or other web-serving mechanisms is recommended. There is no need for supply-chain mitigations such as blocking installs or builds, as the package does not execute malicious code during installation or runtime. Users should avoid opening package contents in a browser and review any CDN or package content serving configurations to prevent exposure.
Malicious code in jhkxcixudnvm1 (npm)
Description
The npm package 'jhkxcixudnvm1' versions 1.0.0 and 1.0.1 contains a malicious HTML file that impersonates a Cloudflare verification page and redirects users to a potentially harmful destination URL. The package does not execute JavaScript during installation or when required in code, so it does not directly compromise build systems or installers. However, if the package contents are served and accessed via a browser (e.g., through a CDN), end-users could be redirected to phishing or malicious sites. The package represents registry abuse rather than a traditional supply-chain code execution vulnerability.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'jhkxcixudnvm1' npm package includes only a package.json and an index.html file declared as the main entry point. The index.html mimics a Cloudflare 'Just a moment...' interstitial page and contains obfuscated JavaScript that reconstructs and redirects to a destination URL after a short delay, forwarding query parameters. No JavaScript runs during npm install or when requiring the package, so the malicious behavior only manifests if the HTML is opened in a browser. This is a case of npm registry abuse hosting a phishing/redirect page, which could harm end-users if the package content is served via a web context. The package does not directly compromise the installer's environment or exfiltrate data during installation.
Potential Impact
End-users who access the package's index.html in a browser context (such as through a CDN serving package contents) may be redirected to a malicious site impersonating Cloudflare, potentially leading to phishing or other harm. There is no direct impact on systems that merely install or require the package in code, as no code execution or credential theft occurs during these operations. However, the presence of this package in an environment may indicate registry abuse and potential exposure to phishing attacks if the malicious HTML is served to users.
Mitigation Recommendations
Since the malicious behavior only occurs if the package's HTML content is served and accessed in a browser, remediation should focus on registry abuse takedown procedures rather than supply-chain blocking. Removing the package from the registry and preventing its distribution via CDNs or other web-serving mechanisms is recommended. There is no need for supply-chain mitigations such as blocking installs or builds, as the package does not execute malicious code during installation or runtime. Users should avoid opening package contents in a browser and review any CDN or package content serving configurations to prevent exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13817
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-fm6c-v7f7-9q2g"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b45bf8831d539cdd125
Added to database: 08/12/2026, 16:11:49 UTC
Last enriched: 08/12/2026, 16:45:15 UTC
Last updated: 08/12/2026, 16:45:15 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.