Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "index.html"
Click on any threat for detailed analysis and mitigation recommendations
The npm package 'dzcvhfruwluwe' versions 1.0.0 and 1.0.1 contains a malicious index.html file that acts as a fake 'Cloudflare Verifying...' page. This page uses obfuscated JavaScript to redirect users' browsers after a short delay to an attacker-controlled external domain. The malicious behavior is client-side and does not execute during package installation or require-time, meaning it does not compromise the developer's environment directly. However, end users who load the HTML file in a browser are redirected to potentially harmful sites. This is a case of registry abuse hosting phishing or malvertising content rather than a traditional supply-chain attack. There is no CVSS score available for this threat. The package should be removed, and any secrets on compromised machines should be rotated due to the risk of full compromise. Join the discussion | GCVE Database | 08/12/2026, 10:29:54 UTC Added: 08/12/2026, 16:11:57 UTC |
The npm package 'egypt0811' version 1.0.0 contains a malicious index.html file that acts as a redirect page styled like a Cloudflare Turnstile interstitial. It includes obfuscated JavaScript that redirects browsers to a phishing or malicious destination URL. The package does not execute code during installation or require-time and does not contain Node.js modules or lifecycle scripts. This behavior indicates registry abuse to host a phishing redirect page rather than a direct supply-chain attack on developers. Any system with this package installed should be considered compromised, and secrets should be rotated immediately. Join the discussion | GCVE Database | 08/12/2026, 10:29:54 UTC Added: 08/12/2026, 16:11:57 UTC |
The npm package 'twcvhjlksdmx' versions 1.0.0 and 1.0.1 contains malicious code embedded in an index.html file that impersonates a Cloudflare interstitial and redirects users who open the HTML file in a browser. The package.json does not execute code during installation or require, so the malicious redirect only triggers if the HTML file is manually opened in a browser. Installation of this package can lead to full system compromise, requiring immediate secret and key rotation and package removal. Join the discussion | GCVE Database | 08/12/2026, 10:29:54 UTC Added: 08/12/2026, 16:11:54 UTC |
The mobicommn npm package version 1.0.0 contains malicious code in the form of an index.html file that mimics a Cloudflare Turnstile challenge. This HTML file, when loaded in a browser, reconstructs a URL from an obfuscated string and redirects the user. The malicious code does not execute during npm install or when the package is imported in Node.js, as Node does not execute HTML files. However, if the HTML file is opened in a browser, it can trigger the redirect. The package is considered fully compromising to any system where it is installed or running, with a recommendation to rotate all secrets and keys from a different machine and remove the package. There is no confirmed patch or fix available at this time. Join the discussion | GCVE Database | 08/12/2026, 10:29:54 UTC Added: 08/12/2026, 16:11:49 UTC |
The npm package 'cvbniydplwe3' version 1.0.0 contains a tarball with only an index.html file that renders a fake Cloudflare Turnstile interstitial and performs a browser-side redirect to a target URL. This package does not execute code during installation or require(), indicating it is not a traditional supply-chain attack but rather an abuse of the npm registry to host phishing or redirect content. Despite no direct code execution on the installer's machine, the presence of this package on a system is considered highly dangerous, as it may indicate compromise. Removal of the package alone may not fully remediate the risk, and secrets should be rotated immediately if the package was installed or run. Join the discussion | GCVE Database | 08/12/2026, 10:29:53 UTC Added: 08/12/2026, 16:11:50 UTC |
The npm package 'cvmbxcjiasdg' versions 1.0.0 and 1.0.1 contains malicious code that serves a fake Cloudflare Turnstile challenge via an index.html file. This HTML page uses obfuscated JavaScript to redirect users' browsers to a constructed URL, forwarding query parameters. The package does not execute code during npm install or require, indicating it is designed to abuse the npm registry as a static host for phishing or redirect lures rather than directly attacking developers. Any system running this package should be considered fully compromised, with immediate secret and key rotation recommended. Join the discussion | GCVE Database | 08/12/2026, 10:29:53 UTC Added: 08/12/2026, 16:11:50 UTC |
The npm package 'mnzjgxciwadk' version 1.0.0 contains a malicious HTML file that acts as a phishing or redirect landing page. The package's main file is an index.html that, when opened in a browser, presents a Cloudflare Turnstile-style challenge and then redirects the user to a URL under the *.olive.club domain using obfuscated JavaScript. This behavior does not trigger during npm install or when requiring/importing the package in code, so the threat targets users opening the HTML file rather than developers or build systems. The package represents registry abuse rather than a direct supply-chain attack. According to one source, any system with this package installed or running should be considered fully compromised, with immediate secret/key rotation recommended. No official patch or fix is indicated. Join the discussion | GCVE Database | 08/12/2026, 10:29:53 UTC Added: 08/12/2026, 16:11:49 UTC |
The npm package 'vkldhcmieru6' version 1.0.0 contains a malicious index.html file that impersonates a Cloudflare Turnstile challenge and redirects browser visitors to a potentially harmful URL. The package does not execute code during installation or when required in Node.js environments, so the threat targets users who visit the hosted HTML content rather than developers installing the package. There is no official patch or remediation information available. Join the discussion | GCVE Database | 08/12/2026, 10:29:53 UTC Added: 08/12/2026, 16:11:48 UTC |
The npm package csbcldfvivwfgd4 version 1.0.0 contains a malicious index.html file that mimics a Cloudflare challenge page and includes obfuscated JavaScript which redirects browser users to a potentially harmful URL. This malicious behavior only triggers when the HTML is rendered in a browser via an npm-backed CDN, not during installation or import in a Node.js environment. There is no code execution or credential theft on the installer's machine, but the package is abused as a phishing or malvertising redirect hosted on the npm registry. Join the discussion | GCVE Database | 08/12/2026, 10:29:52 UTC Added: 08/12/2026, 16:11:50 UTC |
The npm package 'fhj8cv9dkwm4' version 1.0.0 contains malicious code that serves a single index.html mimicking a Cloudflare Turnstile verification page. When rendered in a browser, the obfuscated script redirects users to a constructed '.club' URL with the current page's query parameters. The package does not execute code during installation or require time, but the redirect occurs only when the index.html is served and viewed in a browser. The presence of this package on any computer is considered a full compromise, and all secrets and keys on the affected system should be rotated immediately. Removal of the package alone does not guarantee elimination of all malicious software. No CVSS score is available for this threat. Join the discussion | GCVE Database | 08/12/2026, 10:29:52 UTC Added: 08/12/2026, 16:11:49 UTC |
Showing 1 to 10 of 38 results