ClickFix Phishing Hidden in Malicious npm Packages
Description
A phishing campaign abuses npm package mirrors to host fake Cloudflare Captcha pages embedded in malicious npm packages. These pages are served via trusted mirror domains, increasing their credibility and facilitating phishing attacks such as ClickFix delivery. The campaign uses typosquatted domains and legitimate key-value storage services to redirect victims dynamically. Downloading the packages is not harmful, but accessing the HTML files through mirror URLs exposes users to phishing risks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Threat actors distribute 24 malicious npm packages containing HTML pages that mimic Cloudflare Captcha verification interfaces. These pages are hosted on popular npm mirrors like unpkg, yarn, and npmmirror, leveraging their trusted domains to increase phishing credibility. Early versions redirected victims to a typosquatted Microsoft domain, while later versions dynamically retrieved redirection targets from legitimate key-value storage services. The campaign exploits npm registries as persistent, validated storage for phishing content, demonstrating infrastructure abuse. The packages themselves are harmless to download, but accessing the embedded HTML files through mirror URLs leads to phishing attacks such as ClickFix.
Potential Impact
Users accessing the malicious HTML pages via npm mirrors may be exposed to phishing attacks that impersonate Cloudflare Captcha verification, potentially leading to credential theft or further malware delivery. The use of trusted mirror domains increases the likelihood of user trust and successful phishing. The campaign abuses supply chain infrastructure but does not compromise the npm packages themselves or the npm registry security.
Defensive Guidance
No official patch or fix is applicable since the threat involves abuse of public npm mirrors hosting malicious content. Users and organizations should avoid accessing HTML files directly from npm mirror URLs unless the source is verified. Security teams should educate users about phishing risks involving trusted domains and monitor for suspicious npm packages or mirror URLs. Blocking access to known malicious mirror URLs or implementing web filtering can reduce exposure.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.ox.security/blog/research-clickfix-phishing-npm-packages"]
- Pulse Id
- 6a8e42ad990953414676533f
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainlogin.microsofte.live | — | |
domainapi.keyval.org | — | |
domainkeyval.org | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.keyval.org | — |
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-23958 | — |
Threat ID: 6a8ee183acd9273b49e29112
Added to database: 08/26/2026, 12:52:19 UTC
Last enriched: 09/10/2026, 11:39:05 UTC
Last updated: 10/10/2026, 06:48:15 UTC
Views: 169
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.