cxcbdjxcmncvfg2 @1.0.0
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC
OSV ID
MAL-2026-13801
Ecosystem
npm
Summary
The package contains a single index.html that visually impersonates a Cloudflare 'Just a moment...' challenge page (including a spoofed Ray ID and noindex/nofollow meta as cover). After a 1-second timeout, obfuscator.io-style JavaScript (shuffled string array _0x58ff, base64-charset index decoder _0x4f85, self-defense IIFE hooking console methods) reconstructs a URL on the attacker-controlled domain gin.microcloud.homes (assembled by concatenation to evade static review — 'gin.microc'+'loud.homes') and calls window.location.replace() to forward the visitor, propagating all current query-string parameters. microcloud.homes is not Cloudflare infrastructure; the Cloudflare branding is a lure. The package has no JS main, no lifecycle scripts, and no importable module — its only purpose is to abuse the npm registry as hosting/distribution for a browser-side phishing landing page.
Source: amazon-inspector (0caba01ec3b437a50e1808290e06ae0d084836e6660a0fe90ad56e8cd80b0338)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.