Skip to main content
CyberSingle-sourceMediumDeveloping
5.5

24 malicious npm packages weaponize unpkg for phishing campaigns

Threat actors are distributing 24 npm packages that leverage the unpkg CDN to host fraudulent Cloudflare CAPTCHA pages. By embedding attacker-controlled redirect logic, these packages target end-users rather than developers, marking a shift in supply chain abuse tactics. The extent of the compromise and the total number of affected end-users remain unquantified.

The Hacker News2 days agoengCredibility 59%View source

Score Breakdown

Mosaic Score5.5
Confidence0.9
Significance0.5
Source credibility0.6
Source

Related signals

8 found