AUTO-UPDATED

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have identified a campaign using 24 malicious npm packages to host fake Cloudflare CAPTCHA pages on trusted CDN mirrors for credential harvesting and phishing attacks.

Key Points

  • Researchers at OX Security discovered 24 npm packages serving as free, validated storage for phishing infrastructure.
  • Attackers leverage npm mirrors like unpkg to host HTML files that display deceptive CAPTCHA prompts to users.
  • The campaign uses the legitimate service KeyVal as a dead drop resolver to dynamically update and hide malicious redirect URLs.
  • Initial iterations of the attack targeted a typosquat domain impersonating Microsoft before shifting to public key-value storage APIs.
  • These packages remain accessible on mirrors even after removal from the official npm registry, providing persistent hosting for attackers.

Why it Matters

This campaign highlights a growing trend of threat actors abusing legitimate software supply chain infrastructure to bypass security filters and host malicious content. By turning trusted services into storage for phishing payloads, attackers can effectively evade detection and maintain long-term persistence for their operations.
Internet Published by info@thehackernews.com (The Hacker News)
Read original