By Interestana AI Editorial — AI-drafted, human-overseen. How we report
24 npm Packages Used for Fake Cloudflare CAPTCHA Phishing

Cybersecurity researchers have uncovered a campaign involving 24 npm packages that are being leveraged as phishing infrastructure. These packages exploit unpkg mirrors to host fake Cloudflare CAPTCHA pages, designed to trick users into revealing sensitive information. The threat actor's objective is not to infect developers who install these packages, but rather to utilize the npm ecosystem and its associated infrastructure for malicious purposes. The malware itself consists of a single HTML page embedded within each npm package. While downloading these packages would not directly harm a developer's system, their deployment highlights a sophisticated method of using legitimate platforms for illicit activities.
The campaign specifically targets users by presenting them with deceptive CAPTCHA challenges that mimic legitimate security checks. These fake pages are hosted on unpkg, a content delivery network that serves files from the npm registry. By using unpkg mirrors, the attackers can create a seemingly legitimate hosting environment for their phishing pages, making them harder to detect and block. The use of Cloudflare's branding and CAPTCHA interface is a common tactic in phishing attacks, as it aims to build trust with the victim by appearing as a familiar security measure. Once a user interacts with the fake CAPTCHA, they are likely prompted to enter credentials or other personal data, which is then exfiltrated by the attackers.
This discovery underscores a growing trend where threat actors are increasingly abusing legitimate software supply chains and developer tools for malicious ends. The npm registry, a vast repository of JavaScript packages, is a critical component of modern web development. Its widespread use and the trust developers place in it make it an attractive target for attackers seeking to distribute malware or conduct phishing operations. The researchers' findings indicate that the threat actor is actively using these packages to redirect unsuspecting users to the phishing sites. The specific nature of the "ClickFix-style" fake CAPTCHA pages suggests a focus on credential harvesting, a common goal for phishing campaigns.
The cybersecurity community is actively monitoring this situation to identify and mitigate the threat posed by these malicious npm packages. Developers are advised to exercise caution when installing new packages and to ensure they are sourced from trusted publishers. The exploitation of unpkg mirrors by this campaign highlights the need for enhanced security measures across the entire software supply chain, from package repositories to content delivery networks. The researchers have not yet publicly disclosed the names of the 24 npm packages involved in this operation, but their analysis provides critical insights into the evolving tactics used by cybercriminals to compromise user data and systems.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.