AI called this Suspicious at 90.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for block
- index.html impersonates a Cloudflare security-verification page.
- The Turnstile completion callback contains heavily obfuscated dynamic Function-based code.
- Callback constructs a target URL, copies all window query parameters, then attempts location replacement.
Evidence against
- package.json has no lifecycle scripts, dependencies, or executable JS entrypoint.
- Only observed external endpoints are Cloudflare challenge and informational URLs; no resolved attacker host is present.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source