Find notable cyber news and cases, enriched with sources, timelines, and signals.

24 Npm packages and unpkg fake CAPTCHA phishing campaign

Campaign
First reported
Last updated
Happening score
H score 36
2 unique sources, 2 articles

Summary

Hide ▲

OX Security disclosed a 24 npm packages campaign abusing npm and unpkg mirrors to host fake Cloudflare CAPTCHA pages. The mirrored HTML rendered from trusted mirror domains and used ClickFix-style redirect flows to send visitors onward, with the lure first using login[.]microsofte[.]live and later api.keyval[.]org. The redirect logic was reported to send users to the ChatGPT website at the time of research, while the same setup could be repurposed for other phishing destinations. The activity turns package mirrors into a trusted-hosted delivery layer for phishing pages and other attacker-chosen content.

Related Happenings

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

Lucide proxy npm packages browser DDoS botnet

Malware Activity
H score31 First: 14.07.2026 10:08 Last: 14.07.2026 10:08 Sources 1

About this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...

Google DoubleClick malspam campaign delivering DesckVB RAT

Campaign
H score33 First: 03.06.2026 19:29 Last: 03.06.2026 19:29 Sources 1

About this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...

ChatGPT and Claude phishing and malvertising campaign

Campaign
H score36 First: 01.06.2026 12:30 Last: 01.06.2026 12:30 Sources 1

About this happening: The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...

Openew[.]app cloaked malware download portal

Malware Activity
H score26 First: 29.05.2026 21:21 Last: 29.05.2026 21:21 Sources 1

About this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...

Timeline

  1. 25.08.2026 14:52 3 articles · 13d ago

    Researchers disclose 24 npm packages used to host fake Cloudflare CAPTCHA pages

    Initial Disclosure

    OX Security researchers disclosed a campaign in which 24 npm packages served as free phishing infrastructure on unpkg mirrors, where mirrored HTML rendered fake Cloudflare CAPTCHA pages and sent victims into ClickFix-style redirect flows. The lure initially used login[.]microsofte[.]live, then switched to api.keyval[.]org after Google Chrome Safe Browsing blocked the typosquat; the redirect logic currently sends users to ChatGPT but could be repurposed for other phishing destinations.

    Show sources