Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News by The Hacker News
August 25, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananAug 25, 2026Phishing / Threat Intelligence

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.

“While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware,” OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said.

The list of npm packages, some of which are still available for download, is below –

  • bgzxcuite2
  • prezdentkxheiw
  • egair0810
  • mnteckets
  • airdzticket
  • egypt0811
  • passport811
  • vxhjkseuiaqkb
  • ndmushdkeqe
  • ndmxchdjxn2
  • ndmfguyhoxc3
  • mjsdqwocvn
  • m2fcsfyjkuxb
  • m3fdfocdoewn
  • @worrisome/reutil
  • testdgdbcsd
  • tesgfvbncsdbcv
  • mndsxcusiwlk1
  • mn2adskhweox
  • mn3sadkoiewu
  • mn4xcouzvhus
  • mbxcnsuwgs1
  • skxcmwuncbg2
  • mobiwaefhxc3

The campaign specifically targets mirrors like unpkg. Once mirrored on these services, the HTML file (e.g., “unpkg[.]com/ndmxchdjxn2@1.0.0/index.html”) becomes a live, fully-rendered fake Cloudflare CAPTCHA page that’s hosted on a trusted domain but redirects to ClickFix phishing infrastructure.

As a result, anyone who opens a link that’s hosted on the npm mirror will be tricked into carrying out unintended actions that can lead to the deployment of malware. This involves displaying a fake Cloudflare verification page, which then sends the target to an external website controlled by the attacker.

The HTML page embeds the logic to serve the bogus CAPTCHA verification prompt, as well as JavaScript necessary to send a request to a remote server. Initial iterations of the malware were found to send the request to a typosquat domain that impersonates the Microsoft login page (“login[.]microsofte[.]live”).

But after the domain was added to Google Chrome’s Safe Browsing blocklist, the threat actor behind the campaign is said to have responded by switching to KeyVal (“api.keyval[.]org”), a free, public key-value store that allows developers to set a key-value pair or retrieve a value given a key using a REST API.

In doing so, it turns the legitimate service into a dead drop resolver (DDR) and uses it to extract and decode the URL to which the victim is redirected to.

“Currently the remote logic transfers the user to the legitimate ChatGPT website, but it could be weaponized to deliver ClickFix or any other phishing domains when configured to by the attacker,” the researchers said.

This is not the first time this approach has been abused by bad actors. In October 2025, Socket detailed a set of 175 npm packages that used unpkg.com’s content delivery network (CDN) to host redirect scripts that routed victims to credential harvesting pages as part of a campaign codenamed Beamglea.

“Threat actors keep finding and using new and novel techniques not just to deliver malware, but to use legitimate infrastructure to store their payloads and data,” OX Security said.

“When we think of malware as families of code that steal data directly from the machine they are running on, we can miss other ideas such as infrastructure abuse, using npm and its mirrors as free storage, and persistence – since npm packages can live forever in mirrors even after they are removed from the official stores.”



Source link

The Hacker News

The Hacker News

Next Post

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Recommended.

NetSentries Announces General Availability of AI-Augmented Security Testing

NetSentries Announces General Availability of AI-Augmented Security Testing

May 4, 2026
Analysis: Google Is Getting A Good Deal For Wiz, Actually

Analysis: Google Is Getting A Good Deal For Wiz, Actually

March 20, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio