24 Npm packages and unpkg fake CAPTCHA phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The 24 npm packages campaign is abusing npm and unpkg mirrors to host fake Cloudflare CAPTCHA pages, creating a trusted-hosted redirect layer for phishing and potential malware delivery. The operation matters because the mirrored HTML is rendered on a legitimate domain and can trick users into taking unintended actions. The threat actor also shifted the redirect logic after a Chrome Safe Browsing blocklist action hit one of the lure domains.
Related Happenings
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
Lucide proxy npm packages browser DDoS botnet
Malware Activity
H score31
First: 14.07.2026 10:08
Last: 14.07.2026 10:08
Sources 1
About this happening:
A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Lucide proxy npm packages browser DDoS botnet
Malware ActivityAbout this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Google DoubleClick malspam campaign delivering DesckVB RAT
Campaign
H score33
First: 03.06.2026 19:29
Last: 03.06.2026 19:29
Sources 1
About this happening:
A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Google DoubleClick malspam campaign delivering DesckVB RAT
CampaignAbout this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
ChatGPT and Claude phishing and malvertising campaign
Campaign
H score36
First: 01.06.2026 12:30
Last: 01.06.2026 12:30
Sources 1
About this happening:
The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...
ChatGPT and Claude phishing and malvertising campaign
CampaignAbout this happening: The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...
Openew[.]app cloaked malware download portal
Malware Activity
H score26
First: 29.05.2026 21:21
Last: 29.05.2026 21:21
Sources 1
About this happening:
The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...
Openew[.]app cloaked malware download portal
Malware ActivityAbout this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...
Timeline
-
25.08.2026 14:52 2 articles · 2h ago
Researchers disclose 24 npm packages used to host fake Cloudflare CAPTCHA pages
Initial DisclosureOX Security researchers disclosed a campaign in which 24 npm packages served as free phishing infrastructure on unpkg mirrors, where mirrored HTML rendered fake Cloudflare CAPTCHA pages and sent victims into ClickFix-style redirect flows. The lure initially used login[.]microsofte[.]live, then switched to api.keyval[.]org after Google Chrome Safe Browsing blocked the typosquat; the redirect logic currently sends users to ChatGPT but could be repurposed for other phishing destinations.
Show sources
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages — thehackernews.com — 25.08.2026 14:52
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages — thehackernews.com — 25.08.2026 14:52