Find notable cyber news and cases, enriched with sources, timelines, and signals.

24 Npm packages and unpkg fake CAPTCHA phishing campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The 24 npm packages campaign is abusing npm and unpkg mirrors to host fake Cloudflare CAPTCHA pages, creating a trusted-hosted redirect layer for phishing and potential malware delivery. The operation matters because the mirrored HTML is rendered on a legitimate domain and can trick users into taking unintended actions. The threat actor also shifted the redirect logic after a Chrome Safe Browsing blocklist action hit one of the lure domains.

Related Happenings

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

Lucide proxy npm packages browser DDoS botnet

Malware Activity
H score31 First: 14.07.2026 10:08 Last: 14.07.2026 10:08 Sources 1

About this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...

Google DoubleClick malspam campaign delivering DesckVB RAT

Campaign
H score33 First: 03.06.2026 19:29 Last: 03.06.2026 19:29 Sources 1

About this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...

ChatGPT and Claude phishing and malvertising campaign

Campaign
H score36 First: 01.06.2026 12:30 Last: 01.06.2026 12:30 Sources 1

About this happening: The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...

Openew[.]app cloaked malware download portal

Malware Activity
H score26 First: 29.05.2026 21:21 Last: 29.05.2026 21:21 Sources 1

About this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...

Timeline

  1. 25.08.2026 14:52 2 articles · 2h ago

    Researchers disclose 24 npm packages used to host fake Cloudflare CAPTCHA pages

    Initial Disclosure

    OX Security researchers disclosed a campaign in which 24 npm packages served as free phishing infrastructure on unpkg mirrors, where mirrored HTML rendered fake Cloudflare CAPTCHA pages and sent victims into ClickFix-style redirect flows. The lure initially used login[.]microsofte[.]live, then switched to api.keyval[.]org after Google Chrome Safe Browsing blocked the typosquat; the redirect logic currently sends users to ChatGPT but could be repurposed for other phishing destinations.

    Show sources