threat-intel
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
High
Summary
Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's infrastructure to deliver malware and have previously used similar techniques. The campaign initially used a typosquat domain mimicking Microsoft login pages, but has since switched to a public key-value store for payload delivery.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
