Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
24 Npm Packages Exploit Mirrors for Phishing via Fake CAPTCHA

24 Npm Packages Exploit Mirrors for Phishing via Fake CAPTCHA

Posted on August 25, 2026 By CWS

Cybersecurity experts have uncovered a sophisticated phishing campaign involving 24 npm packages that exploit unpkg mirrors to host deceptive Cloudflare CAPTCHA pages. This innovative use of npm infrastructure poses a significant threat, redirecting unsuspecting users to malicious sites under the guise of legitimate services.

Npm Packages as Phishing Tools

The campaign leverages npm packages not to directly infect developers but to utilize npm’s registry and mirrors as a secure storage medium for phishing materials. As reported by OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko, the campaign manipulates npm to facilitate the storage of simple HTML pages that serve as phishing platforms.

The list of affected npm packages, some still available for download, includes names like bgzxcuite2, prezdentkxheiw, and egair0810. These packages target npm mirrors, particularly unpkg, to render fake Cloudflare CAPTCHA pages hosted on trusted domains, misleading users into engaging with phishing infrastructure.

The Mechanics of the Phishing Campaign

Once mirrored, the HTML file becomes a live fake CAPTCHA page, designed to redirect victims to external sites controlled by attackers. The HTML page contains embedded logic and JavaScript to execute the phishing operation, initially pointing to a domain impersonating Microsoft’s login page. However, after being blocked by Google Chrome’s Safe Browsing, the threat actors adapted by using KeyVal, a public key-value store, to redirect victims.

This approach effectively turns KeyVal into a dead drop resolver, enabling the attackers to extract and decode URLs for redirection. While the current setup redirects users to the legitimate ChatGPT site, the attackers have the capability to modify configurations, potentially leading users to harmful phishing domains.

Implications and Historical Context

This method of exploiting npm mirrors is not unprecedented. In October 2025, a similar tactic was documented involving 175 npm packages using unpkg.com’s CDN to facilitate credential harvesting. This historical precedent highlights the ongoing challenge cybersecurity experts face in combating infrastructure abuse.

OX Security emphasizes the persistent innovation of threat actors in utilizing legitimate platforms for malicious purposes. By exploiting npm as a persistent storage solution, attackers ensure their phishing tools remain accessible long after removal from official repositories.

This campaign underscores the need for vigilance and advanced threat detection to protect against such sophisticated phishing strategies. As threat landscapes evolve, so too must the security measures designed to counteract them.

The Hacker News Tags:CAPTCHA, ChatGPT, ClickFix, Cloudflare, Cybersecurity, dead drop resolver, fake pages, JavaScript, KeyVal, Malware, NPM, OX Security, Phishing, threat intelligence, unpkg

Post navigation

Previous Post: Scammers Use Fake Microsoft Scan to Trick Users
Next Post: Cyber-Physical Systems Training to Enhance ICS Security

Related Posts

⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More ⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More The Hacker News
Konni Uses Phishing to Spread EndRAT via KakaoTalk Konni Uses Phishing to Spread EndRAT via KakaoTalk The Hacker News
Global Authorities Dismantle Criminal VPN Used by Ransomware Global Authorities Dismantle Criminal VPN Used by Ransomware The Hacker News
Hotel Wi-Fi Exploited to Distribute Surveillance Trojan Hotel Wi-Fi Exploited to Distribute Surveillance Trojan The Hacker News
251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and Elasticsearch 251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and Elasticsearch The Hacker News
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Teams Exploited in SynkLoader Cyber Attacks
  • U.S. Targets Iran-Linked Cybercriminals with Sanctions
  • CISA Red Team Uncovers Security Flaws in Critical Infrastructure
  • FTP Banners Used for New Malware Delivery Tactics
  • Alice Secures $140 Million to Combat AI Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Teams Exploited in SynkLoader Cyber Attacks
  • U.S. Targets Iran-Linked Cybercriminals with Sanctions
  • CISA Red Team Uncovers Security Flaws in Critical Infrastructure
  • FTP Banners Used for New Malware Delivery Tactics
  • Alice Secures $140 Million to Combat AI Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark