Listen to the episode
TLDR
Attackers are uploading malicious HTML files to public npm package mirrors, then sharing links that look like innocent Cloudflare CAPTCHA verification pages. Once the visitor clicks, the fake CAPTCHA silently redirects them to credential...
How it works
Attackers are uploading malicious HTML files to public npm package mirrors, then sharing links that look like innocent Cloudflare CAPTCHA verification pages. Once the visitor clicks, the fake CAPTCHA silently redirects them to credential...
Red flags
- CAPTCHA challenge appearing on a link that came from an unsolicited message, email, or social media DM. The page host domain looks like an npm mirror or package CDN rather than the real site you intended to visit. After completing the CAPTCHA you are bounced to a login page, wallet connect, or download prompt unrelated to your task
What to do
- 1Never click CAPTCHA links delivered by strangers
- 2navigate to the destination site manually. Check the full URL bar before interacting with any verification prompt. Report suspicious npm hosted pages to the npm security team and your browser vendor
Source
bleepingcomputer
Source reviewed by Mythos Forensic Team
https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/FAQ
Is Fake Cloudflare CAPTCHA pages hosted on npm mirrors used in phishing attacks a real scam pattern?
Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.
What are the first warning signs?
CAPTCHA challenge appearing on a link that came from an unsolicited message, email, or social media DM. The page host domain looks like an npm mirror or package CDN rather than the real site you intended to visit. After completing the CAPTCHA you are bounced to a login page, wallet connect, or download prompt unrelated to your task
What should I do first?
Never click CAPTCHA links delivered by strangers; navigate to the destination site manually. Check the full URL bar before interacting with any verification prompt. Report suspicious npm hosted pages to the npm security team and your browser vendor
Can LegalAudit check my case?
Yes. Start a free chat and paste the message, link, sender, or payment details for triage.