24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Ravie LakshmananAug 25, 2026Phishing / Threat Intelligence

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pag

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Ravie LakshmananAug 25, 2026Phishing / Threat Intelligence

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.

“While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware,” OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said.

The list of npm packages, some of which are still available for download, is below –

  • bgzxcuite2
  • prezdentkxheiw
  • egair0810
  • mnteckets
  • airdzticket
  • egypt0811
  • passport811
  • vxhjkseuiaqkb
  • ndmushdkeqe
  • ndmxchdjxn2
  • ndmfguyhoxc3
  • mjsdqwocvn
  • m2fcsfyjkuxb
  • m3fdfocdoewn
  • @worrisome/reutil
  • testdgdbcsd
  • tesgfvbncsdbcv
  • mndsxcusiwlk1
  • mn2adskhweox
  • mn3sadkoiewu
  • mn4xcouzvhus
  • mbxcnsuwgs1
  • skxcmwuncbg2
  • mobiwaefhxc3

The campaign specifically targets mirrors like unpkg. Once mirrored on these services, the HTML file (e.g., “unpkg[.]com/ndmxchdjxn2@1.0.0/index.html”) becomes a live, fully-rendered fake Cloudflare CAPTCHA page that’s hosted on a trusted domain but redirects to ClickFix phishing infrastructure.

As a result, anyone who opens a link that’s hosted on the npm mirror will be tricked into carrying out unintended actions that can lead to the deployment of malware. This involves displaying a fake Cloudflare verification page, which then sends the target to an external website controlled by the attacker.

The HTML page embeds the logic to serve the bogus CAPTCHA verification prompt, as well as JavaScript necessary to send a request to a remote server. Initial iterations of the malware were found to send the request to a typosquat domain that impersonates the Microsoft login page (“login[.]microsofte[.]live”).

But after the domain was added to Google Chrome’s Safe Browsing blocklist, the threat actor behind the campaign is said to have responded by switching to KeyVal (“api.keyval[.]org”), a free, public key-value store that allows developers to set a key-value pair or retrieve a value given a key using a REST API.

In doing so, it turns the legitimate service into a dead drop resolver (DDR) and uses it to extract and decode the URL to which the victim is redirected to.

“Currently the remote logic transfers the user to the legitimate ChatGPT website, but it could be weaponized to deliver ClickFix or any other phishing domains when configured to by the attacker,” the researchers said.

This is not the first time this approach has been abused by bad actors. In October 2025, Socket detailed a set of 175 npm packages that used unpkg.com’s content delivery network (CDN) to host redirect scripts that routed victims to credential harvesting pages as part of a campaign codenamed Beamglea.

“Threat actors keep finding and using new and novel techniques not just to deliver malware, but to use legitimate infrastructure to store their payloads and data,” OX Security said.

“When we think of malware as families of code that steal data directly from the machine they are running on, we can miss other ideas such as infrastructure abuse, using npm and its mirrors as free storage, and persistence – since npm packages can live forever in mirrors even after they are removed from the official stores.”

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.