Malicious code in yangming8 (npm)
The npm package 'yangming8' version 1.0.0 contains a malicious payload in its single file index.html, which serves a fake Cloudflare verification page and then redirects users to a phishing site impersonating MicroCloud. The package does not execute code on installation or require, but abuses npm registry and CDN mirrors to host a browser-side credential phishing page. The risk to developers installing the package is minimal, but end users accessing the HTML via CDN URLs are targeted. There is no CVSS score available for this threat.
AI Analysis
Technical Summary
The 'yangming8' npm package version 1.0.0 contains only an index.html file declared as its main entry point. This HTML file displays a fake Cloudflare 'Just a moment...' page and, after a short delay, executes obfuscated JavaScript that reconstructs and redirects the browser to a phishing domain impersonating MicroCloud. The package lacks lifecycle scripts, JavaScript entry points, dependencies, or library code, so installing or requiring it does not execute the payload on the installer's machine. Instead, the package abuses the npm registry and CDN mirrors (such as unpkg and jsdelivr) as static hosting for a browser-side credential phishing page. The installer-side risk is minimal, but the distribution method enables phishing attacks on users who load the HTML via CDN URLs. The package should be removed from the registry to prevent abuse.
Potential Impact
End users who load the index.html file from the 'yangming8' package via npm CDN mirrors are redirected to a phishing site designed to steal credentials by impersonating MicroCloud. Developers installing or requiring the package are not directly exposed to code execution or payload delivery. The malicious package abuses the npm ecosystem for static hosting of phishing content, potentially leading to credential theft from users. There is no evidence of active exploitation in the wild or direct system compromise from installation.
Mitigation Recommendations
Since the malicious payload is delivered via the package's HTML file served through CDN mirrors, users and developers should avoid loading content from this package's CDN URLs. The package version 1.0.0 should be removed from the npm registry to prevent further abuse. There is no indication of code execution on installation, so removing the package from developer environments is precautionary. Rotate any credentials that may have been exposed if the phishing site was accessed. Patch status is not applicable as this is a malicious package rather than a software vulnerability with a fix.
Malicious code in yangming8 (npm)
Description
The npm package 'yangming8' version 1.0.0 contains a malicious payload in its single file index.html, which serves a fake Cloudflare verification page and then redirects users to a phishing site impersonating MicroCloud. The package does not execute code on installation or require, but abuses npm registry and CDN mirrors to host a browser-side credential phishing page. The risk to developers installing the package is minimal, but end users accessing the HTML via CDN URLs are targeted. There is no CVSS score available for this threat.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'yangming8' npm package version 1.0.0 contains only an index.html file declared as its main entry point. This HTML file displays a fake Cloudflare 'Just a moment...' page and, after a short delay, executes obfuscated JavaScript that reconstructs and redirects the browser to a phishing domain impersonating MicroCloud. The package lacks lifecycle scripts, JavaScript entry points, dependencies, or library code, so installing or requiring it does not execute the payload on the installer's machine. Instead, the package abuses the npm registry and CDN mirrors (such as unpkg and jsdelivr) as static hosting for a browser-side credential phishing page. The installer-side risk is minimal, but the distribution method enables phishing attacks on users who load the HTML via CDN URLs. The package should be removed from the registry to prevent abuse.
Potential Impact
End users who load the index.html file from the 'yangming8' package via npm CDN mirrors are redirected to a phishing site designed to steal credentials by impersonating MicroCloud. Developers installing or requiring the package are not directly exposed to code execution or payload delivery. The malicious package abuses the npm ecosystem for static hosting of phishing content, potentially leading to credential theft from users. There is no evidence of active exploitation in the wild or direct system compromise from installation.
Defensive Guidance
Since the malicious payload is delivered via the package's HTML file served through CDN mirrors, users and developers should avoid loading content from this package's CDN URLs. The package version 1.0.0 should be removed from the npm registry to prevent further abuse. There is no indication of code execution on installation, so removing the package from developer environments is precautionary. Rotate any credentials that may have been exposed if the phishing site was accessed. Patch status is not applicable as this is a malicious package rather than a software vulnerability with a fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13846
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-f3hv-h6vj-6j6r"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b43bf8831d539cdcf1c
Added to database: 08/12/2026, 16:11:47 UTC
Last enriched: 08/12/2026, 16:37:05 UTC
Last updated: 08/13/2026, 02:35:40 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.