Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in yangming8 (npm)

0
High
Published: 08/12/2026 (08/12/2026, 10:29:52 UTC)
Source: GCVE Database
Product: yangming8

Description

The npm package 'yangming8' version 1.0.0 contains a malicious payload in its single file index.html, which serves a fake Cloudflare verification page and then redirects users to a phishing site impersonating MicroCloud. The package does not execute code on installation or require, but abuses npm registry and CDN mirrors to host a browser-side credential phishing page. The risk to developers installing the package is minimal, but end users accessing the HTML via CDN URLs are targeted. There is no CVSS score available for this threat.

Affected software

npmghsa
yangming8
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:37:05 UTC

Technical Analysis

The 'yangming8' npm package version 1.0.0 contains only an index.html file declared as its main entry point. This HTML file displays a fake Cloudflare 'Just a moment...' page and, after a short delay, executes obfuscated JavaScript that reconstructs and redirects the browser to a phishing domain impersonating MicroCloud. The package lacks lifecycle scripts, JavaScript entry points, dependencies, or library code, so installing or requiring it does not execute the payload on the installer's machine. Instead, the package abuses the npm registry and CDN mirrors (such as unpkg and jsdelivr) as static hosting for a browser-side credential phishing page. The installer-side risk is minimal, but the distribution method enables phishing attacks on users who load the HTML via CDN URLs. The package should be removed from the registry to prevent abuse.

Potential Impact

End users who load the index.html file from the 'yangming8' package via npm CDN mirrors are redirected to a phishing site designed to steal credentials by impersonating MicroCloud. Developers installing or requiring the package are not directly exposed to code execution or payload delivery. The malicious package abuses the npm ecosystem for static hosting of phishing content, potentially leading to credential theft from users. There is no evidence of active exploitation in the wild or direct system compromise from installation.

Defensive Guidance

Since the malicious payload is delivered via the package's HTML file served through CDN mirrors, users and developers should avoid loading content from this package's CDN URLs. The package version 1.0.0 should be removed from the npm registry to prevent further abuse. There is no indication of code execution on installation, so removing the package from developer environments is precautionary. Rotate any credentials that may have been exposed if the phishing site was accessed. Patch status is not applicable as this is a malicious package rather than a software vulnerability with a fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13846
Osv Schema Version
1.7.4
Aliases
["GHSA-f3hv-h6vj-6j6r"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b43bf8831d539cdcf1c

Added to database: 08/12/2026, 16:11:47 UTC

Last enriched: 08/12/2026, 16:37:05 UTC

Last updated: 08/13/2026, 02:35:40 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses