bmgki3g6fh3 @1.0.0
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC
OSV ID
MAL-2026-13789
Ecosystem
npm
Summary
The package contains a single file, index.html, declared as main . The page renders a spoofed Cloudflare 'Just a moment...' / Turnstile 'security verification' interstitial (fake Ray ID alongside a real Turnstile widget) and, on completion, runs an obfuscator.io-wrapped script that assembles a URL starting with 'https://lo' + decoded fragments + '/', appends the current query string, and navigates window.location to it. No install lifecycle scripts (preinstall/install/postinstall/prepare) are declared and main points at a non-JS file, so npm install and require() do not execute any code on a developer machine or build system. The hostile behavior only manifests if a browser is pointed at index.html. This is registry abuse for hosting phishing/redirect infrastructure rather than a supply-chain attack against installers.
Source: amazon-inspector (9212dc22bc5983b7b163b7851e76596bda812485709581a8dd61475630db4450)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.