AI called this Malicious at 97.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.html presents a fake Cloudflare verification page.
- The Turnstile callback, error, expiry, timeout, and unsupported handlers all invoke obfuscated code.
- That code creates a hidden target URL, copies current query parameters, and redirects via window.location.assign.
- Obfuscation includes Function-based global access and anti-analysis logic around the redirect.
Evidence against
- package.json has no lifecycle scripts or dependencies.
- No local file, environment, or credential harvesting was found.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source