Attackers abuse npm and its mirrors to host fake CAPTCHA phishing pages
Researchers at OX Security found a campaign using two dozen npm packages as free phishing infrastructure rather than as malware aimed at developers. Each package is just a single HTML page, harmless to install, but once served through npm content-delivery mirrors like unpkg it becomes a live, fully rendered fake Cloudflare CAPTCHA page hosted on a trusted domain. The page then redirects victims to ClickFix-style phishing infrastructure, and while it currently forwards to a legitimate site, it can be reconfigured to deliver any phishing payload. The trick is not infecting people who install the packages, but abusing the registry and its mirrors as validated, reputable storage for attacker content.
- Check
- Treat fake CAPTCHA and ClickFix pages as hostile even when served from trusted domains like unpkg, and educate users not to run commands or steps a CAPTCHA prompt tells them to perform.
- Affected
- Anyone lured to a fake CAPTCHA page hosted on a trusted npm mirror; the pages redirect to ClickFix phishing, exploiting the reputation of legitimate infrastructure to bypass suspicion and some blocking.
- Fix
- Monitor and filter for HTML content served from package-mirror domains, block known phishing and ClickFix infrastructure, apply reputation-aware web filtering rather than trusting domains outright, and train users on fake CAPTCHA lures.