npm Mirrors Used for Fake Cloudflare CAPTCHA Phish

The Hacker News · Medium sophistication
Last updated August 26, 2026

Researchers found a real phishing campaign abusing npm packages and unpkg mirrors to host a convincing fake Cloudflare CAPTCHA page on a trusted domain. Victims who click the mirrored link are redirected to attacker-controlled infrastructure that could deliver ClickFix-style prompts or credential theft. The actors also rotated their backend from a Microsoft typosquat domain to a legitimate KeyVal service to hide the final redirect destination.

How the Attack Worked

Attackers published 24 npm packages, each containing a single HTML page. The goal was not to infect developers through package installation, but to use npm and mirror services like unpkg as trusted, validated storage for phishing content. Once mirrored, the HTML file renders as a live, fully rendered fake Cloudflare CAPTCHA page hosted on a domain that most users and security tools consider trustworthy. After a victim completes the fake verification step, the page redirects them to attacker-controlled infrastructure, which could deliver ClickFix-style prompts or credential theft.

Hiding the Redirect Behind Legitimate Services

The page embeds JavaScript that contacts a remote server to determine where to send the victim next. Early versions of this logic pointed to a typosquat domain impersonating the Microsoft login page. After that domain was added to a browser Safe Browsing blocklist, the actors switched to a legitimate third-party service to resolve the final redirect, turning it into what researchers describe as a dead drop resolver. This domain rotation shows how quickly attackers can adapt when one piece of infrastructure gets blocked.

Why It Succeeded

The campaign relies on misplaced trust in domain reputation. A CAPTCHA hosted on a known developer mirror looks legitimate at a glance, and the redirect logic is hidden behind a backend call rather than visible in the link itself. Because the current redirect destination is benign, the page can pass casual inspection while remaining ready to be repointed to malicious content.

What to Watch For

  • Verification or CAPTCHA pages hosted on package mirrors or CDNs instead of expected company domains
  • Verification steps that redirect immediately to an external website
  • Links containing unusual versioned package paths

Building Resistance

Treat any CAPTCHA or verification prompt that redirects elsewhere as suspicious, regardless of the hosting domain's reputation. Encourage employees and developers to report unexpected verification pages so security teams can investigate before the redirect logic is weaponized against benign destinations.

Key findings

  • Attackers published 24 npm packages containing a single HTML page, not to infect developers via install, but to use npm and mirrors as "safe, validated storage" for phishing content.
  • The mirrored HTML (e.g., on unpkg) renders a fake Cloudflare CAPTCHA page on a trusted domain and then redirects victims to attacker-controlled infrastructure.
  • Early versions contacted a Microsoft-impersonating typosquat domain (login.microsofte.live) but later switched to the legitimate KeyVal service (api.keyval.org) to resolve the final redirect.
  • Researchers warn the current redirect destination is benign (ChatGPT) but could be reconfigured to send victims to ClickFix or other phishing pages.

Who’s being targeted

  • Commonly targeted roles: All employees, Developers, IT support/helpdesk, Security awareness and SOC teams.
  • Affected industries: Software development, Technology / IT, Any organization whose users click links to trusted developer CDNs/mirrors.
  • Attack channels: email, website.
  • Impersonated: Cloudflare verification (hosted via unpkg mirror), Cloudflare verification page + backend resolver.

Red flags to watch for

  • The 'Cloudflare CAPTCHA' is hosted on a developer package mirror (unpkg) instead of a company-owned or expected domain.
  • The page performs an unexpected redirect to an external site after the CAPTCHA step.
  • The link originates from an unusual npm package path/versioned URL.
  • Page uses a 'trusted' brand verification theme but relies on unusual third-party lookups to resolve where to send the user next.
  • The backend changes over time (domain rotation) to avoid blocking.
  • Redirect destination is not visible up front and can be swapped by the attacker.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers use npm packages in this campaign?

They published 24 npm packages containing a single HTML page, not to infect developers who install them, but to use npm and mirrors like unpkg as trusted, validated storage for phishing content.

What happens after a victim sees the fake CAPTCHA?

The mirrored HTML renders a fake Cloudflare CAPTCHA page on a trusted domain and then redirects victims to attacker-controlled infrastructure, which could deliver ClickFix-style prompts or credential theft.

Why did the attackers switch backend domains?

Early versions contacted a Microsoft-impersonating typosquat domain, but after it was added to a Safe Browsing blocklist, the actors switched to a legitimate service to hide the final redirect destination.

Is the current redirect destination dangerous?

Researchers note the current redirect goes to a benign destination, but warn it could be reconfigured at any time to send victims to phishing or malware pages.

Read the video transcript

You click a link, see a Cloudflare CAPTCHA on a trusted site, and think, "Safe." That’s exactly the trap. Attackers published npm packages that are just one HTML file. When mirrored on unpkg, that file becomes a fake Cloudflare page that then silently sends you off to their next site. Behind that page, scripts call out to backends like login.microsofte.live or api.keyval.org to decide where to send you next. Today it might land on ChatGPT; tomorrow it could be a ClickFix credential phish. If you ever see a Cloudflare-style CAPTCHA on an unpkg, npm, or other package mirror URL, stop and report it to security, don’t click through.

Categories

Similar attacks

Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake CAPTCHA ‘ClickFix’ Spreads Lunex Stealer

Fake CAPTCHA ‘ClickFix’ Spreads Lunex Stealer

Attackers compromised legitimate Ukrainian websites and showed visitors a fake CAPTCHA/Cloudflare-style “verification” prompt to trick them into installing malware. The infection chain drops Lunex (aka Psychedelic Stealer), which disables security monitoring using a vulnerable AMD driver and then…

September 26, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Fake “ChatGPT” GPT Uses ClickFix to Drop RAT

Fake “ChatGPT” GPT Uses ClickFix to Drop RAT

Researchers found a real malware campaign where attackers abused ChatGPT “CustomGPTs” and Google sponsored search results to funnel victims to a fake ChatGPT experience. Victims are shown a fake “Service Availability Notice” and pushed to a “backup domain” that looks like a Cloudflare CAPTCHA,…

September 30, 2026
CSuite Phish Steals M365 Sessions, Installs RMM

CSuite Phish Steals M365 Sessions, Installs RMM

Researchers observed a real phishing campaign (“CSuite”) heavily targeting U.S. organizations using familiar business-themed lures (DocuSign, Adobe, Zoom/Meet, Dropbox, Microsoft 365). After a victim engages, the attackers either steal Microsoft 365 sessions (enabling mailbox takeover and fraud) or…

September 30, 2026
Placeholder Domain Now Pushes ClickFix Malware

Placeholder Domain Now Pushes ClickFix Malware

A commonly used documentation placeholder domain, third-party.com, was registered by an unknown party and is now serving a ClickFix social-engineering lure to Windows users. The page pretends to run a Cloudflare security check, silently poisons the clipboard, and tells victims to paste and run a…

September 24, 2026