National Cyber Warfare Foundation (NCWF)

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages


0 user ratings
2026-08-25 12:38:03
milo
Blue Team (CND)
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.

"While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.