24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Summary
Cybersecurity researchers have identified 24 npm packages being used as free phishing infrastructure. These packages redirect users to fake Cloudflare CAPTCHA pages designed to steal credentials, similar to ClickFix-style attacks.
IFF Assessment
FOE
This campaign represents a new method for threat actors to distribute phishing pages, making it harder for defenders to block them.
Defender Context
This discovery highlights the evolving tactics of phishing campaigns, where legitimate platforms like npm are abused for malicious infrastructure. Defenders should be aware of such techniques and ensure robust phishing detection and user education.