OX Security identified a campaign distributing fake Cloudflare Captcha pages through 24 malicious npm packages. The threat actors exploit npm mirrors like unpkg, yarn, and npmmirror as free hosting infrastructure for phishing content. Each package contains an HTML page that displays a fraudulent Cloudflare verification interface. When accessed through mirror sites, these pages appear on trusted domains, increasing their credibility. The initial versions redirected victims to a typosquatted Microsoft domain, while later iterations used legitimate key-value storage services to dynamically retrieve redirection targets. Although downloading the packages is harmless, accessing the HTML files through mirror URLs can lead to ClickFix delivery or other phishing attacks. The campaign demonstrates infrastructure abuse where npm registries serve as persistent, validated storage for malicious payloads.
Created: 2026-08-26
Indicatorsは見つかっていない。
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。