Threat actors are abusing npm packages and mirrors like UNPKG and npmmirror to host malicious HTML pages that impersonate Cloudflare CAPTCHAs and redirect users to attacker-controlled destinations. The campaign uses legitimate infrastructure as free hosting for phishing pages, with some redirects pointing to Microsoft login themes, ChatGPT, or dynamically controlled URLs. #Cloudflare #npm #UNPKG #npmmirror #Turnstile
Keypoints
- Attackers hide malicious HTML inside npm packages and mirrors.
- The pages impersonate Cloudflare verification screens with Turnstile CAPTCHA.
- Opening mirrored files in a browser serves the content from legitimate domains.
- Redirect targets have included Microsoft and ChatGPT-themed destinations.
- Researchers advise treating direct HTML access on npm mirrors as suspicious.