Cybersecurity researchers have identified a campaign using 24 malicious npm packages to host fake Cloudflare CAPTCHA pages on trusted CDN mirrors for credential harvesting and phishing attacks.
Key Points
- Researchers at OX Security discovered 24 npm packages serving as free, validated storage for phishing infrastructure.
- Attackers leverage npm mirrors like unpkg to host HTML files that display deceptive CAPTCHA prompts to users.
- The campaign uses the legitimate service KeyVal as a dead drop resolver to dynamically update and hide malicious redirect URLs.
- Initial iterations of the attack targeted a typosquat domain impersonating Microsoft before shifting to public key-value storage APIs.
- These packages remain accessible on mirrors even after removal from the official npm registry, providing persistent hosting for attackers.