{"id":2526,"date":"2026-08-25T17:12:22","date_gmt":"2026-08-25T17:12:22","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2526"},"modified":"2026-08-25T17:12:22","modified_gmt":"2026-08-25T17:12:22","slug":"24-npm-packages-abuse-unpkg-mirrors-to-host-fake-cloudflare-captcha-pages","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2526","title":{"rendered":"24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 25, 2026<\/span><\/span><span class=\"p-tags\">Phishing \/ Threat Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg6XLRNvnqL3SBGR1Hrv9eIrUlQ8Tr6RhA2dwxYZYKiNoh7qZwgA8aGATBHsDqQCD6ilgXGlLdMIs54WZ5jEW4G_TjJiFyQ6u5acpyUE5vdHa-0E-SZwIliX9sTQqcOw6pNG0TlGm-lUQrvdEEKdSOnB-Mep1U7GVVW-qOQiD1PEDItN-lDv3mOjexfo29x\/s1700-e365\/cf-phishing.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.<\/p>\n<p>\u00abWhile the malware is simply a single HTML page inside the npm package, and while downloading it wouldn&#8217;t do harm, the threat actor\u2019s use of npm isn&#8217;t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware,\u00bb OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko <a href=\"https:\/\/www.ox.security\/blog\/research-clickfix-phishing-npm-packages\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>The list of npm packages, some of which are still available for download, is below &#8211;<\/p>\n<ul>\n<li>bgzxcuite2<\/li>\n<li>prezdentkxheiw<\/li>\n<li>egair0810<\/li>\n<li>mnteckets<\/li>\n<li>airdzticket<\/li>\n<li>egypt0811<\/li>\n<li>passport811<\/li>\n<li>vxhjkseuiaqkb<\/li>\n<li>ndmushdkeqe<\/li>\n<li>ndmxchdjxn2<\/li>\n<li>ndmfguyhoxc3<\/li>\n<li>mjsdqwocvn<\/li>\n<li>m2fcsfyjkuxb<\/li>\n<li>m3fdfocdoewn<\/li>\n<li>@worrisome\/reutil<\/li>\n<li>testdgdbcsd<\/li>\n<li>tesgfvbncsdbcv<\/li>\n<li>mndsxcusiwlk1<\/li>\n<li>mn2adskhweox<\/li>\n<li>mn3sadkoiewu<\/li>\n<li>mn4xcouzvhus<\/li>\n<li>mbxcnsuwgs1<\/li>\n<li>skxcmwuncbg2<\/li>\n<li>mobiwaefhxc3<\/li>\n<\/ul>\n<p>The campaign specifically targets mirrors like unpkg. Once mirrored on these services, the HTML file (e.g., \u00abunpkg[.]com\/ndmxchdjxn2@1.0.0\/index.html\u00bb) becomes a live, fully-rendered fake Cloudflare CAPTCHA page that&#8217;s hosted on a trusted domain but redirects to ClickFix phishing infrastructure.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>As a result, anyone who opens a link that&#8217;s hosted on the npm mirror will be tricked into carrying out unintended actions that can lead to the deployment of malware. This involves displaying a fake Cloudflare verification page, which then sends the target to an external website controlled by the attacker.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The HTML page embeds the logic to serve the bogus CAPTCHA verification prompt, as well as JavaScript necessary to send a request to a remote server. Initial iterations of the malware were found to send the request to a typosquat domain that impersonates the Microsoft login page (\u00ablogin[.]microsofte[.]live\u00bb).<\/p>\n<p>But after the domain was added to Google Chrome&#8217;s Safe Browsing blocklist, the threat actor behind the campaign is said to have responded by switching to <a href=\"https:\/\/keyval.org\/#\" target=\"_blank\">KeyVal<\/a> (\u00abapi.keyval[.]org\u00bb), a free, public key-value store that allows developers to set a key-value pair or retrieve a value given a key using a REST API.<\/p>\n<p>In doing so, it turns the legitimate service into a dead drop resolver (<a href=\"https:\/\/www.cc.gatech.edu\/news\/hiding-plain-sight-disrupting-malwares-secret-web-dead-drops\" target=\"_blank\">DDR<\/a>) and uses it to extract and decode the URL to which the victim is redirected to.<\/p>\n<p>\u00abCurrently the remote logic transfers the user to the legitimate ChatGPT website, but it could be weaponized to deliver ClickFix or any other phishing domains when configured to by the attacker,\u00bb the researchers said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>This is not the first time this approach has been abused by bad actors. In October 2025, Socket detailed a set of 175 npm packages that used unpkg.com&#8217;s content delivery network (CDN) to host redirect scripts that routed victims to credential harvesting pages as part of a campaign codenamed Beamglea.<\/p>\n<p>\u00abThreat actors keep finding and using new and novel techniques not just to deliver malware, but to use legitimate infrastructure to store their payloads and data,\u00bb OX Security said.<\/p>\n<p>\u00abWhen we think of malware as families of code that steal data directly from the machine they are running on, we can miss other ideas such as infrastructure abuse, using npm and its mirrors as free storage, and persistence \u2013 since npm packages can live forever in mirrors even after they are removed from the official stores.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 25, 2026Phishing \/ Threat Intelligence Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2527,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[383,1413,927,150,1109,3157,39,35,2358,3156],"class_list":["post-2526","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abuse","tag-captcha","tag-cloudflare","tag-fake","tag-host","tag-mirrors","tag-npm","tag-packages","tag-pages","tag-unpkg"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2526","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2526"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2526\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2527"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2526"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}