logo

Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.

ID: 0f59df11-708b-5bc7-811d-2575a64daa5a

STIX ID: report--0f59df11-708b-5bc7-811d-2575a64daa5a

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Mayura Kathir

...
...

OX Security identified a campaign of 24 malicious npm packages that host identical HTML impersonating Cloudflare verification pages on trusted npm mirrors (e.g., unpkg.com). The packages act as disposable hosting for phishing pages that contact attacker-controlled infrastructure or remote key-value services to determine redirect destinations; while current redirects led to benign sites, the technique can enable credential phishing, ClickFix social-engineering flows, or malware delivery. Security teams are advised to treat direct .html requests to npm mirrors as suspicious, review proxy/DNS/secure web gateway logs for package-version paths ending in .html, and warn users never to run OS commands prompted by in-browser CAPTCHAs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.