importantSYS.SOURCE: The Hacker News• 2026-08-25T17:22:43+05:30
24 npm Packages Exploit Unpkg Mirrors for Phishing via Fake Cloudflare CAPTCHA Pages
24 npm packages are being used to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. Attackers leverage legitimate services like KeyVal to dynamically resolve phishing URLs, exploiting open-source ecosystems for malicious purposes.
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.
"While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
*** END OF TRANSMISSION ***