Threats Tagged 'mal-2026-13808'
View all threats tagged with 'mal-2026-13808'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-13808'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in fghvbmniwu (npm) 0 The npm package 'fghvbmniwu' versions 1.0.0 and 1.0.1 contains malicious code that serves a heavily obfuscated HTML page embedding a Cloudflare-branded Turnstile widget. This page redirects browsers to a constructed URL at runtime, indicating abuse of the npm registry as a free CDN for phishing or redirect landing pages. The malicious behavior only affects browsers loading the file via CDN mirrors and does not execute code during package installation or require/import in Node.js environments. Despite this, a security source warns that any system with this package installed or running should be considered fully compromised, recommending immediate secret/key rotation and package removal, though removal may not fully eliminate the threat. No official patch or fix is documented. Join the discussion | GCVE Database | 08/12/2026, 10:29:53 UTC Added: 08/12/2026, 16:11:50 UTC |
Showing 1 to 1 of 1 result