Prove it. Don't just claim it.
Font size: +

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the

At a glance

  • Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Sign in to read full story
In order for you to continue reading the full contents of the post, you will need to login first

Copyright

© SecurityTalent.com — original summary and analysis

'NovaCookies' Kit Steals Microsoft 365 Sessions fo...
91 Vulnerabilities Patched in Spring Application F...

Related Posts

 

Comments

Already Registered? Login Here
No comments made yet. Be the first to submit a comment