xhjckswqivb @1.0.0
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC
OSV ID
MAL-2026-13844
Ecosystem
npm
Summary
Package contains only index.html and package.json. The HTML mimics a Cloudflare Turnstile challenge and, when loaded in a browser, assembles an obfuscated URL from the string fragments 'gin.microl' and 'ive.club/' and redirects the visitor to https://login.microlive.club/ with the original query string appended. package.json declares no preinstall/install/postinstall/prepare lifecycle scripts, and main points at the HTML file, so npm install and require do not execute any of this code on the installer. The victim of the artifact is an end-user who visits the served HTML, not a developer who installs the package.
Source: amazon-inspector (9a9d37b433e22c980e67c0a2991612592959f6998df3928a6a09792ecf4860bb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.