AI called this Malicious at 96.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.html masquerades as a Cloudflare security-verification page.
- onTurnstileComplete contains heavily obfuscated JavaScript and anti-analysis code.
- The callback builds a concealed target URL, copies all current query parameters, then replaces window.location.
- package.json ships index.html as the sole main file.
Evidence against
- package.json has no lifecycle scripts or dependencies.
- No local file writes, child-process use, or Node-side credential harvesting were found.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source