Fake npm Packages Used to Host Phishing CAPTCHA Scams
Security researchers have uncovered a campaign involving 24 npm packages that are not designed to infect developers who install them, but instead act as free hosting infrastructure for phishing pages. Each package contains a single HTML file that, when accessed through unpkg (a public content delivery network that mirrors npm packages), displays a fake Cloudflare CAPTCHA page.
These fake CAPTCHA pages are part of a technique known as "ClickFix," where victims are tricked into copying and running a malicious command on their own computer, often believing they are completing a routine security check. Because the phishing content is hosted on a trusted, legitimate service like unpkg, it can bypass some security filters and appear more credible to unsuspecting users.
This campaign highlights how attackers are increasingly abusing legitimate developer tools and public infrastructure to distribute scams, rather than relying solely on traditional malicious downloads. For small businesses, this means staff could encounter convincing fake security checks even on pages that appear to come from reputable sources.