Opening index.html in a browser shows a fake Cloudflare check, then the packed script posts a hidden host key and AES-decrypts a remote reply that supplies redirect_url. npm install does not run this page, but the shipped file is a live command-and-control interstitial, not a library.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgindex.html impersonates a Cloudflare waiting page titled Just a moment and loads Turnstile from challenges.cloudflare.com.
index.htmlView on unpkg · L7A packed inline script stores hostKey and aesKeyBase64, POSTs JSON with fetch, then AES-decrypts the reply with crypto.subtle.
index.htmlView on unpkg · L183A packed inline script stores hostKey and aesKeyBase64, POSTs JSON with fetch, then AES-decrypts the reply with crypto.subtle.
index.htmlView on unpkg · L183A packed inline script stores hostKey and aesKeyBase64, POSTs JSON with fetch, then AES-decrypts the reply with crypto.subtle.
index.htmlView on unpkg · L183After the challenge, the script reads redirect_url from that decrypted control data and onTurnstileComplete calls window.__challengeRedirect.
index.htmlView on unpkg · L178After the challenge, the script reads redirect_url from that decrypted control data and onTurnstileComplete calls window.__challengeRedirect.
index.htmlView on unpkg · L183The package has a random name, ships only index.html as main, and is not a usable Node library.
package.jsonView on unpkg · L1This report applies to luftmvfiwgxydes@1.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgindex.html impersonates a Cloudflare waiting page titled Just a moment and loads Turnstile from challenges.cloudflare.com.
index.htmlView on unpkg · L7A packed inline script stores hostKey and aesKeyBase64, POSTs JSON with fetch, then AES-decrypts the reply with crypto.subtle.
index.htmlView on unpkg · L183A packed inline script stores hostKey and aesKeyBase64, POSTs JSON with fetch, then AES-decrypts the reply with crypto.subtle.
index.htmlView on unpkg · L183A packed inline script stores hostKey and aesKeyBase64, POSTs JSON with fetch, then AES-decrypts the reply with crypto.subtle.
index.htmlView on unpkg · L183After the challenge, the script reads redirect_url from that decrypted control data and onTurnstileComplete calls window.__challengeRedirect.
index.htmlView on unpkg · L178After the challenge, the script reads redirect_url from that decrypted control data and onTurnstileComplete calls window.__challengeRedirect.
index.htmlView on unpkg · L183The package has a random name, ships only index.html as main, and is not a usable Node library.
package.jsonView on unpkg · L1