CyberNotableSingle-sourceDeveloping
5.5
24 malicious npm packages weaponize unpkg for phishing campaigns
The Hacker News·2 days ago
Malicious actors are leveraging npm mirrors to host fraudulent Cloudflare CAPTCHA pages, facilitating credential harvesting and phishing redirects. This technique exploits the trusted reputation of package repositories to bypass traditional security filters. The scale of the campaign remains uncertain, though it highlights persistent vulnerabilities in software supply chain infrastructure.