ClickFix Phishing Hidden in Malicious npm Packages
OX Security identified a campaign distributing fake Cloudflare Captcha pages through 24 malicious npm packages. The threat actors exploit npm mirrors like unpkg, yarn, and npmmirror as free hosting infrastructure for phishing content. Each package contains an HTML page that displays a fraudulent Cloudflare verification interface. When accessed through mirror sites, these pages appear on trusted domains, increasing their credibility. The initial versions redirected victims to a typosquatted Microsoft domain, while later iterations used legitimate key-value storage services to dynamically retrieve redirection targets. Although downloading the packages is harmless, accessing the HTML files through mirror URLs can lead to ClickFix delivery or other phishing attacks. The campaign demonstrates infrastructure abuse where npm registries serve as persistent, validated storage for malicious payloads.
Indicators of Compromise
- domain: login.microsofte.live
- domain: api.keyval.org
- url: https://api.keyval.org
- domain: keyval.org
- cve: CVE-2026-23958
ClickFix Phishing Hidden in Malicious npm Packages
Description
OX Security identified a campaign distributing fake Cloudflare Captcha pages through 24 malicious npm packages. The threat actors exploit npm mirrors like unpkg, yarn, and npmmirror as free hosting infrastructure for phishing content. Each package contains an HTML page that displays a fraudulent Cloudflare verification interface. When accessed through mirror sites, these pages appear on trusted domains, increasing their credibility. The initial versions redirected victims to a typosquatted Microsoft domain, while later iterations used legitimate key-value storage services to dynamically retrieve redirection targets. Although downloading the packages is harmless, accessing the HTML files through mirror URLs can lead to ClickFix delivery or other phishing attacks. The campaign demonstrates infrastructure abuse where npm registries serve as persistent, validated storage for malicious payloads.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.ox.security/blog/research-clickfix-phishing-npm-packages"]
- Adversary
- null
- Pulse Id
- 6a8e42ad990953414676533f
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainlogin.microsofte.live | — | |
domainapi.keyval.org | — | |
domainkeyval.org | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.keyval.org | — |
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-23958 | — |
Threat ID: 6a8ee183acd9273b49e29112
Added to database: 08/26/2026, 12:52:19 UTC
Last updated: 08/26/2026, 18:23:33 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.