24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Read full story on The Hacker News
Share
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
AI disclosure

Summary

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.