24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.

“While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actorโ€™s use of npm isn’t to infect developers who install it, but to use the

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Response to AI slop is from Robin Williams

Response to AI slop is from Robin Williams Source: Hacker News

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service

It is a sign of the times that Amazon gets to call this fair use

It is a sign of the times that Amazon gets to call this fair use Source: Hacker News