Opening index.html loads a Cloudflare Turnstile script and, on each completion/error callback, redirects the browser to an obfuscated target while forwarding URL parameters.
Static reason
No blocking static signals were detected.
Trigger
A user opens index.html and the Turnstile callback fires.
Impact
Unconsented navigation can transfer URL-borne tokens or identifiers to an obscured destination.
Mechanism
Obfuscated browser redirect with query-string forwarding.
Rationale
This is not an install-time npm attack, but the only runtime payload is a deceptive, obfuscated redirect that forwards caller-controlled URL data. The concrete redirect behavior warrants a warning despite no confirmed credential capture.
Network endpoints1
challenges.cloudflare.com