HackerFeeds

CyberSecurity News

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News
· August 25, 2026

AI summary

Cybersecurity researchers have uncovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages. These packages serve as free phishing infrastructure, redirecting users to ClickFix-style fake CAPTCHA pages. The malware consists of a single HTML page within the npm package, which is harmless to download. However, the threat actor's intention is not to infect developers who install the package, but rather to leverage the npm packages for malicious purposes. The packages are being used to support phishing activities, taking advantage of the infrastructure provided by unpkg mirrors.

Read the full article at The Hacker Newsthehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.