Home Active 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
ActiveCybersecurity

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Share
24-npm-packages-abuse-unpkg-mirrors-to-host-fake-cloudflare-captcha-pages
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Share

Ravie LakshmananAug 25, 2026Phishing / Threat Intelligence

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.

“While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware,” OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said.

The list of npm packages, some of which are still available for download, is below –

  • bgzxcuite2
  • prezdentkxheiw
  • egair0810
  • mnteckets
  • airdzticket
  • egypt0811
  • passport811
  • vxhjkseuiaqkb
  • ndmushdkeqe
  • ndmxchdjxn2
  • ndmfguyhoxc3
  • mjsdqwocvn
  • m2fcsfyjkuxb
  • m3fdfocdoewn
  • @worrisome/reutil
  • testdgdbcsd
  • tesgfvbncsdbcv
  • mndsxcusiwlk1
  • mn2adskhweox
  • mn3sadkoiewu
  • mn4xcouzvhus
  • mbxcnsuwgs1
  • skxcmwuncbg2
  • mobiwaefhxc3

The campaign specifically targets mirrors like unpkg. Once mirrored on these services, the HTML file (e.g., “unpkg[.]com/ndmxchdjxn2@1.0.0/index.html”) becomes a live, fully-rendered fake Cloudflare CAPTCHA page that’s hosted on a trusted domain but redirects to ClickFix phishing infrastructure.

As a result, anyone who opens a link that’s hosted on the npm mirror will be tricked into carrying out unintended actions that can lead to the deployment of malware. This involves displaying a fake Cloudflare verification page, which then sends the target to an external website controlled by the attacker.

The HTML page embeds the logic to serve the bogus CAPTCHA verification prompt, as well as JavaScript necessary to send a request to a remote server. Initial iterations of the malware were found to send the request to a typosquat domain that impersonates the Microsoft login page (“login[.]microsofte[.]live”).

But after the domain was added to Google Chrome’s Safe Browsing blocklist, the threat actor behind the campaign is said to have responded by switching to KeyVal (“api.keyval[.]org”), a free, public key-value store that allows developers to set a key-value pair or retrieve a value given a key using a REST API.

In doing so, it turns the legitimate service into a dead drop resolver (DDR) and uses it to extract and decode the URL to which the victim is redirected to.

“Currently the remote logic transfers the user to the legitimate ChatGPT website, but it could be weaponized to deliver ClickFix or any other phishing domains when configured to by the attacker,” the researchers said.

This is not the first time this approach has been abused by bad actors. In October 2025, Socket detailed a set of 175 npm packages that used unpkg.com’s content delivery network (CDN) to host redirect scripts that routed victims to credential harvesting pages as part of a campaign codenamed Beamglea.

“Threat actors keep finding and using new and novel techniques not just to deliver malware, but to use legitimate infrastructure to store their payloads and data,” OX Security said.

“When we think of malware as families of code that steal data directly from the machine they are running on, we can miss other ideas such as infrastructure abuse, using npm and its mirrors as free storage, and persistence – since npm packages can live forever in mirrors even after they are removed from the official stores.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Share
Related Articles

Ceuta crisis: anti-migrant ‘invasion’ rhetoric threatens Europe’s food supply and economy

In August 2026, a deep humanitarian crisis unfolded in Ceuta, a small...

Analysis: Evergrande Tycoon’s Life Sentence Serves as Scapegoat for China’s Real Estate Policy Failures

News AnalysisWhen a court in southern China sentenced Evergrande founder Hui Ka...

The False Refuge: Why Turning to China Is No Answer for Disillusioned Western Allies

CommentaryPeriods of geopolitical frustration often tempt nations into strategic overcorrections. Today, as...

Going to China or Hong Kong? The Questions You Should Ask Before You Fly

CommentaryOn Aug. 18, I met my friend at Pearson International Airport in...