24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Summary

Cybersecurity researchers have identified 24 npm packages being used as free phishing infrastructure. These packages redirect users to fake Cloudflare CAPTCHA pages designed to steal credentials, similar to ClickFix-style attacks.

IFF Assessment

FOE

This campaign represents a new method for threat actors to distribute phishing pages, making it harder for defenders to block them.

Defender Context

This discovery highlights the evolving tactics of phishing campaigns, where legitimate platforms like npm are abused for malicious infrastructure. Defenders should be aware of such techniques and ensure robust phishing detection and user education.

Read Full Story →