AI called this Malicious at 96.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.html is the declared main entry and embeds a fake Cloudflare verification page.
- The Turnstile completion callback contains heavily obfuscated JavaScript.
- Callback constructs an obfuscated external HTTPS URL and redirects window.location.
- It copies all current URL query parameters to the redirect destination.
Evidence against
- package.json has no lifecycle scripts or dependencies.
- No filesystem, credential, or child-process access appears in the package.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source