Security
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
The Hacker News·August 25, 2026·1 min read
Cybersecurity researchers disclosed a campaign using 24 npm packages as free phishing infrastructure, redirecting to ClickFix-style fake CAPTCHA pages. The packages host a single HTML page, and the threat actor uses npm not to infect developers but to leverage the platform for hosting malicious content. The pages mimic Cloudflare CAPTCHAs.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
