The Hacker News
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Attackers exploited 24 npm packages to host fake Cloudflare CAPTCHA pages for phishing attacks. The malicious packages leverage unpkg mirrors as free infrastructure to redirect users to ClickFix-style scam pages. This highlights supply chain risks where legitimate package repositories enable phishing campaigns.
AI summary · generated with Claude
https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html