Opening index.html runs obfuscated browser code that resolves a concealed destination and redirects the visitor. The destination is selected through a remote policy request.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgA Turnstile completion callback invokes the hidden redirect function.
index.htmlView on unpkg · L178This report applies to kamafhbnowct@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgA Turnstile completion callback invokes the hidden redirect function.
index.htmlView on unpkg · L178