logo

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

ID: 665f366b-fffb-5614-b5ca-641e24b3a887

STIX ID: report--665f366b-fffb-5614-b5ca-641e24b3a887

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: [email protected] (The Hacker News)

...
...

OX Security researchers disclosed a campaign that uploaded 24 npm packages containing single HTML pages which, when served via mirrors like unpkg, render fake Cloudflare CAPTCHA pages and redirect victims to credential-harvesting infrastructure; the actor has switched from a typosquat Microsoft domain to using api.keyval.org as a dead-drop resolver to control redirect targets, and several packages remain available—demonstrating infrastructure abuse of trusted package/CDN mirrors to host persistent phishing pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.