Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
24 Npm Packages Exploit Mirrors for Phishing via Fake CAPTCHA

24 Npm Packages Exploit Mirrors for Phishing via Fake CAPTCHA

Posted on August 25, 2026 By CWS

Cybersecurity experts have uncovered a sophisticated phishing campaign involving 24 npm packages that exploit unpkg mirrors to host deceptive Cloudflare CAPTCHA pages. This innovative use of npm infrastructure poses a significant threat, redirecting unsuspecting users to malicious sites under the guise of legitimate services.

Npm Packages as Phishing Tools

The campaign leverages npm packages not to directly infect developers but to utilize npm’s registry and mirrors as a secure storage medium for phishing materials. As reported by OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko, the campaign manipulates npm to facilitate the storage of simple HTML pages that serve as phishing platforms.

The list of affected npm packages, some still available for download, includes names like bgzxcuite2, prezdentkxheiw, and egair0810. These packages target npm mirrors, particularly unpkg, to render fake Cloudflare CAPTCHA pages hosted on trusted domains, misleading users into engaging with phishing infrastructure.

The Mechanics of the Phishing Campaign

Once mirrored, the HTML file becomes a live fake CAPTCHA page, designed to redirect victims to external sites controlled by attackers. The HTML page contains embedded logic and JavaScript to execute the phishing operation, initially pointing to a domain impersonating Microsoft’s login page. However, after being blocked by Google Chrome’s Safe Browsing, the threat actors adapted by using KeyVal, a public key-value store, to redirect victims.

This approach effectively turns KeyVal into a dead drop resolver, enabling the attackers to extract and decode URLs for redirection. While the current setup redirects users to the legitimate ChatGPT site, the attackers have the capability to modify configurations, potentially leading users to harmful phishing domains.

Implications and Historical Context

This method of exploiting npm mirrors is not unprecedented. In October 2025, a similar tactic was documented involving 175 npm packages using unpkg.com’s CDN to facilitate credential harvesting. This historical precedent highlights the ongoing challenge cybersecurity experts face in combating infrastructure abuse.

OX Security emphasizes the persistent innovation of threat actors in utilizing legitimate platforms for malicious purposes. By exploiting npm as a persistent storage solution, attackers ensure their phishing tools remain accessible long after removal from official repositories.

This campaign underscores the need for vigilance and advanced threat detection to protect against such sophisticated phishing strategies. As threat landscapes evolve, so too must the security measures designed to counteract them.

The Hacker News Tags:CAPTCHA, ChatGPT, ClickFix, Cloudflare, Cybersecurity, dead drop resolver, fake pages, JavaScript, KeyVal, Malware, NPM, OX Security, Phishing, threat intelligence, unpkg

Post navigation

Previous Post: Scammers Use Fake Microsoft Scan to Trick Users
Next Post: Cyber-Physical Systems Training to Enhance ICS Security

Related Posts

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware The Hacker News
Linux Kernel Vulnerabilities Highlight Security Concerns Linux Kernel Vulnerabilities Highlight Security Concerns The Hacker News
Digital Parasite Threats Redefine Cybersecurity in 2026 Digital Parasite Threats Redefine Cybersecurity in 2026 The Hacker News
3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 The Hacker News
Perseus Malware Targets Android Devices for Financial Fraud Perseus Malware Targets Android Devices for Financial Fraud The Hacker News
See Threats to Your Industry & Country in Real Time See Threats to Your Industry & Country in Real Time The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark