Back to all news
Security

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News·August 25, 2026·1 min read
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers disclosed a campaign using 24 npm packages as free phishing infrastructure, redirecting to ClickFix-style fake CAPTCHA pages. The packages host a single HTML page, and the threat actor uses npm not to infect developers but to leverage the platform for hosting malicious content. The pages mimic Cloudflare CAPTCHAs.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store