Opening the published HTML runs an obfuscated browser payload disguised as a Cloudflare challenge. It resolves a concealed remote destination and redirects the visitor.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page loads Cloudflare Turnstile and invokes a redirect callback after challenge completion.
index.htmlView on unpkg · L9The page loads Cloudflare Turnstile and invokes a redirect callback after challenge completion.
index.htmlView on unpkg · L178The package’s only entrypoint is an HTML file, not a legitimate npm library module.
package.jsonView on unpkg · L1This report applies to kamafhbnowct@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page loads Cloudflare Turnstile and invokes a redirect callback after challenge completion.
index.htmlView on unpkg · L9The page loads Cloudflare Turnstile and invokes a redirect callback after challenge completion.
index.htmlView on unpkg · L178The package’s only entrypoint is an HTML file, not a legitimate npm library module.
package.jsonView on unpkg · L1