Skip to main content
EPSS 0.5%top 57%

ClickFix Phishing Hidden in Malicious npm Packages

0
Medium
Published: 08/26/2026 (08/26/2026, 01:34:37 UTC)
Source: AlienVault OTX General

Description

A phishing campaign abuses npm package mirrors to host fake Cloudflare Captcha pages embedded in malicious npm packages. These pages are served via trusted mirror domains, increasing their credibility and facilitating phishing attacks such as ClickFix delivery. The campaign uses typosquatted domains and legitimate key-value storage services to redirect victims dynamically. Downloading the packages is not harmful, but accessing the HTML files through mirror URLs exposes users to phishing risks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 11:39:05 UTC

Technical Analysis

Threat actors distribute 24 malicious npm packages containing HTML pages that mimic Cloudflare Captcha verification interfaces. These pages are hosted on popular npm mirrors like unpkg, yarn, and npmmirror, leveraging their trusted domains to increase phishing credibility. Early versions redirected victims to a typosquatted Microsoft domain, while later versions dynamically retrieved redirection targets from legitimate key-value storage services. The campaign exploits npm registries as persistent, validated storage for phishing content, demonstrating infrastructure abuse. The packages themselves are harmless to download, but accessing the embedded HTML files through mirror URLs leads to phishing attacks such as ClickFix.

Potential Impact

Users accessing the malicious HTML pages via npm mirrors may be exposed to phishing attacks that impersonate Cloudflare Captcha verification, potentially leading to credential theft or further malware delivery. The use of trusted mirror domains increases the likelihood of user trust and successful phishing. The campaign abuses supply chain infrastructure but does not compromise the npm packages themselves or the npm registry security.

Defensive Guidance

No official patch or fix is applicable since the threat involves abuse of public npm mirrors hosting malicious content. Users and organizations should avoid accessing HTML files directly from npm mirror URLs unless the source is verified. Security teams should educate users about phishing risks involving trusted domains and monitor for suspicious npm packages or mirror URLs. Blocking access to known malicious mirror URLs or implementing web filtering can reduce exposure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.ox.security/blog/research-clickfix-phishing-npm-packages"]
Pulse Id
6a8e42ad990953414676533f

Indicators of Compromise

Domain

ValueDescriptionCopy
domainlogin.microsofte.live
—
domainapi.keyval.org
—
domainkeyval.org
—

Url

ValueDescriptionCopy
urlhttps://api.keyval.org
—

Cve

ValueDescriptionCopy
cveCVE-2026-23958
—

Threat ID: 6a8ee183acd9273b49e29112

Added to database: 08/26/2026, 12:52:19 UTC

Last enriched: 09/10/2026, 11:39:05 UTC

Last updated: 10/10/2026, 06:48:15 UTC

Views: 169

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses