Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in jhkxcixudnvm1 (npm)

0
Medium
Published: 08/12/2026 (08/12/2026, 10:29:52 UTC)
Source: GCVE Database
Product: jhkxcixudnvm1

Description

The npm package 'jhkxcixudnvm1' versions 1.0.0 and 1.0.1 contains a malicious HTML file that impersonates a Cloudflare verification page and redirects users to a potentially harmful destination URL. The package does not execute JavaScript during installation or when required in code, so it does not directly compromise build systems or installers. However, if the package contents are served and accessed via a browser (e.g., through a CDN), end-users could be redirected to phishing or malicious sites. The package represents registry abuse rather than a traditional supply-chain code execution vulnerability.

Affected software

npmghsa
jhkxcixudnvm1
Affected versions
=1.0.1=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:45:15 UTC

Technical Analysis

The 'jhkxcixudnvm1' npm package includes only a package.json and an index.html file declared as the main entry point. The index.html mimics a Cloudflare 'Just a moment...' interstitial page and contains obfuscated JavaScript that reconstructs and redirects to a destination URL after a short delay, forwarding query parameters. No JavaScript runs during npm install or when requiring the package, so the malicious behavior only manifests if the HTML is opened in a browser. This is a case of npm registry abuse hosting a phishing/redirect page, which could harm end-users if the package content is served via a web context. The package does not directly compromise the installer's environment or exfiltrate data during installation.

Potential Impact

End-users who access the package's index.html in a browser context (such as through a CDN serving package contents) may be redirected to a malicious site impersonating Cloudflare, potentially leading to phishing or other harm. There is no direct impact on systems that merely install or require the package in code, as no code execution or credential theft occurs during these operations. However, the presence of this package in an environment may indicate registry abuse and potential exposure to phishing attacks if the malicious HTML is served to users.

Mitigation Recommendations

Since the malicious behavior only occurs if the package's HTML content is served and accessed in a browser, remediation should focus on registry abuse takedown procedures rather than supply-chain blocking. Removing the package from the registry and preventing its distribution via CDNs or other web-serving mechanisms is recommended. There is no need for supply-chain mitigations such as blocking installs or builds, as the package does not execute malicious code during installation or runtime. Users should avoid opening package contents in a browser and review any CDN or package content serving configurations to prevent exposure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13817
Osv Schema Version
1.7.4
Aliases
["GHSA-fm6c-v7f7-9q2g"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b45bf8831d539cdd125

Added to database: 08/12/2026, 16:11:49 UTC

Last enriched: 08/12/2026, 16:45:15 UTC

Last updated: 08/12/2026, 16:45:15 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses