gdwkh6vcbu @1.0.0
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC
OSV ID
MAL-2026-13810
Ecosystem
npm
Summary
Package gdwkh6vcbu@1.0.0 ships a single index.html declared as main , with no JavaScript entry point, no install lifecycle hooks, and placeholder-only metadata (random 10-character name, no description/author/repository/license, files list containing only index.html). The HTML impersonates a Cloudflare Turnstile 'Just a moment...' verification page. On Turnstile completion, obfuscator.io-style code (string-array + _0x2637 base64 decoder) constructs a URL whose host ends in 'loud.homes/', propagates the current page's query parameters to that URL, and calls window.location.assign to redirect the visitor. The package is not usable as a Node module; its sole purpose is to be served over npm-backed CDN mirrors (unpkg/jsdelivr) as a phishing landing/redirector page. npm install does not execute code on the installing developer, but the artifact abuses the npm namespace/CDN to host and distribute obfuscated phishing content targeting end-user browsers.
Source: amazon-inspector (149331c58c86a1da87dcdde4ec9e7f780a879ca2283946418cfff31077797bd4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.