Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in ms_aidc_com_tw (npm)

0
Critical
Published: 08/12/2026 (08/12/2026, 10:29:52 UTC)
Source: GCVE Database
Product: ms_aidc_com_tw

Description

The npm package ms_aidc_com_tw (version 1.0.0) contains malicious code that impersonates a Microsoft-branded Taiwanese domain and serves a fake Cloudflare Turnstile security verification page. Upon user interaction, it executes heavily obfuscated JavaScript to redirect victims to the legitimate Microsoft login page with attacker-controlled parameters, enabling OAuth-consent phishing. Installing or running this package may fully compromise the affected computer, risking exposure of stored secrets and keys.

Affected software

npmghsa
ms_aidc_com_tw
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:42:33 UTC

Technical Analysis

The ms_aidc_com_tw npm package (version 1.0.0) is a malicious package that hosts only an index.html page rendering a fake Cloudflare Turnstile verification. The obfuscated JavaScript collects query parameters and redirects users to login.microsoftonline.com with these parameters preserved, facilitating an adversary-in-the-middle OAuth-consent phishing attack. The package name mimics a legitimate Microsoft Taiwanese corporate domain to deceive users. This abuse of the npm registry serves as hosting infrastructure for Microsoft 365 credential harvesting. The obfuscation techniques include rotating string arrays, RC4/base64 decoding, and anti-debugging measures to conceal the phishing logic.

Potential Impact

Any system with this package installed or running should be considered fully compromised. The attacker may gain access to Microsoft 365 credentials through OAuth-consent phishing, potentially leading to unauthorized access to sensitive accounts and data. All secrets and keys stored on the compromised system should be considered exposed and require immediate rotation. Removal of the package alone does not guarantee elimination of all malicious software or attacker persistence.

Defensive Guidance

Remove the ms_aidc_com_tw package immediately if installed. Rotate all secrets, credentials, and keys stored on the affected system from a separate, trusted device. Because full compromise is likely, conduct a thorough investigation and consider rebuilding the affected system to ensure removal of any persistent malicious components. There is no official patch or fix for this package as it is a malicious artifact rather than a software vulnerability. Avoid installing packages from untrusted sources and verify package authenticity before use.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13828
Osv Schema Version
1.7.4
Aliases
["GHSA-2fg7-gfq8-c24g"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b44bf8831d539cdcfda

Added to database: 08/12/2026, 16:11:48 UTC

Last enriched: 08/12/2026, 16:42:33 UTC

Last updated: 08/12/2026, 16:42:33 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses