OX Security identified 24 npm packages carrying the same fake Cloudflare CAPTCHA HTML file. The pages redirected visitors through changing attacker controlled services, including a typosquatted Microsoft login domain and the KeyVal public key value store, before presenting a ClickFix lure that asked victims...
Published byEdited with GPT-5.6 LunaImages generated with GPT Image 1.5
Research answer

Create a landscape editorial hero image for this Studio Global article: What did OX Security uncover about the campaign using 24 malicious npm packages and trusted mirrors such as unpkg as phishing infrastructure. Article summary: OX Security found that 24 npm packages carried the same malicious HTML file: a fake Cloudflare CAPTCHA. The packages were not designed to infect developers on installation; instead, attackers used npm and automatically s. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
OX Security uncovered a campaign in which 24 npm packages contained the same malicious HTML file: a fake Cloudflare CAPTCHA page. The packages were not primarily designed to infect developers who installed them. Instead, npm and automatically synchronized mirrors such as unpkg gave the attackers a trusted-looking place to host phishing content and distribute links to it. 2
17
The campaign exploited the credibility and availability of the npm ecosystem in an unusual way. The malicious payload was a single HTML page rather than a conventional package compromise that executed code during installation. A visitor who opened the relevant file through npm or a package mirror could see a Cloudflare-style verification screen under a familiar service domain. 2
17
That distinction matters: an npm download was not necessarily an infection event. The attackers’ goal was to get people to click externally distributed links to the hosted page, using npm’s registry and mirrors as a reliable delivery channel. 17
The fake CAPTCHA page acted as the first step in a redirect chain. OX Security reported that earlier versions contacted a typosquatted Microsoft domain, while subsequent reporting identified changing destinations and infrastructure, including domains such as microcloud[.]homes and login[.]microsofte[.]live. 2
18
The campaign also used KeyVal, a public key-value store, as a resolver or “dead drop” for destination information. That gave operators a way to change where victims were sent without needing to republish the same HTML file in every package. 21
This infrastructure makes takedown more complicated. Removing a package from npm does not automatically invalidate every URL that may already point to a synchronized mirror copy. Reporting on the campaign noted that some package files and mirror-hosted pages remained available after registry removals. 17
18
The CAPTCHA was a lure, not a genuine security check. The page directed victims to copy, paste, and run a command on their own systems. That is the defining ClickFix pattern: instead of exploiting a software vulnerability, the attacker persuades the victim to execute the malicious command with the user’s own permissions. 20
25
Fake verification pages are especially effective because they borrow familiar browser and security branding. Research on similar campaigns describes verification buttons or instructions that quietly place a command on the clipboard and then guide the victim through keyboard shortcuts or an operating-system prompt. 26
28
The practical lesson is simple: a CAPTCHA should never require a user to open a shell, PowerShell, Terminal, or Run dialog and execute copied text.
Each package generally received about 50–300 weekly downloads before removal, according to OX Security. 2 Those figures describe registry activity, not the total number of people who may have encountered the phishing pages through direct links or mirror URLs.
That makes ordinary package-download metrics an incomplete measure of the campaign’s intended reach. The packages functioned as a network of hosted landing pages, while the attackers could distribute the URLs through phishing messages, compromised websites, or other channels. 2
17
The npm campaign is best understood as an infrastructure variation on a broader ClickFix model. Across reported campaigns, attackers combine a familiar lure—such as a CAPTCHA, browser error, fake update, or software utility—with instructions that persuade victims to run a command themselves. Proofpoint described the technique as a growing method for delivering malware, while Microsoft has documented related evolutions that use disruption and social engineering to increase the chance of execution. 22
25
27
The supplied evidence does not establish that the 24-package campaign was operated by the same actor behind PavinLoader, EtherHiding, Amatera Stealer, fake OpenAI Codex pages targeting Mac developers, ACR Stealer, or the alleged earlier Beamglea operation. Those examples may illustrate the broader convergence around user-assisted execution, but they should not be treated as confirmed parts of the OX Security campaign without additional evidence.
This case expands the definition of an npm supply-chain threat. A package does not need to run malicious code during installation to become useful to an attacker. A static HTML file, hosted through a trusted registry and its mirrors, can provide the front door for a phishing operation.
For developers and security teams, the key controls are to inspect unexpected npm and CDN URLs, treat fake verification instructions as social engineering, monitor browsers and endpoints for suspicious command execution, and avoid running commands copied from webpages. The most important warning sign is not the CAPTCHA itself—it is any request to bypass normal security behavior by pasting and executing text.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
OX Security identified 24 npm packages carrying the same fake Cloudflare CAPTCHA HTML file.
OX Security identified 24 npm packages carrying the same fake Cloudflare CAPTCHA HTML file. The pages redirected visitors through changing attacker controlled services, including a typosquatted Microsoft login domain and the KeyVal public key value store, before presenting a ClickFix lure that asked victims...
The findings fit the broader rise of ClickFix social engineering, but the supplied evidence does not prove that this npm campaign shared an operator with other named ClickFix operations.
OX Security identified 24 npm packages carrying the same fake Cloudflare CAPTCHA HTML file. The pages redirected visitors through changing attacker controlled services, including a typosquatted Microsoft login domain and the KeyVal public key value store, before presenting a ClickFix lure that asked victims...
Published byEdited with GPT-5.6 LunaImages generated with GPT Image 1.5
Research answer

Create a landscape editorial hero image for this Studio Global article: What did OX Security uncover about the campaign using 24 malicious npm packages and trusted mirrors such as unpkg as phishing infrastructure. Article summary: OX Security found that 24 npm packages carried the same malicious HTML file: a fake Cloudflare CAPTCHA. The packages were not designed to infect developers on installation; instead, attackers used npm and automatically s. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
OX Security uncovered a campaign in which 24 npm packages contained the same malicious HTML file: a fake Cloudflare CAPTCHA page. The packages were not primarily designed to infect developers who installed them. Instead, npm and automatically synchronized mirrors such as unpkg gave the attackers a trusted-looking place to host phishing content and distribute links to it. 2
17
The campaign exploited the credibility and availability of the npm ecosystem in an unusual way. The malicious payload was a single HTML page rather than a conventional package compromise that executed code during installation. A visitor who opened the relevant file through npm or a package mirror could see a Cloudflare-style verification screen under a familiar service domain. 2
17
That distinction matters: an npm download was not necessarily an infection event. The attackers’ goal was to get people to click externally distributed links to the hosted page, using npm’s registry and mirrors as a reliable delivery channel. 17
The fake CAPTCHA page acted as the first step in a redirect chain. OX Security reported that earlier versions contacted a typosquatted Microsoft domain, while subsequent reporting identified changing destinations and infrastructure, including domains such as microcloud[.]homes and login[.]microsofte[.]live. 2
18
The campaign also used KeyVal, a public key-value store, as a resolver or “dead drop” for destination information. That gave operators a way to change where victims were sent without needing to republish the same HTML file in every package. 21
This infrastructure makes takedown more complicated. Removing a package from npm does not automatically invalidate every URL that may already point to a synchronized mirror copy. Reporting on the campaign noted that some package files and mirror-hosted pages remained available after registry removals. 17
18
The CAPTCHA was a lure, not a genuine security check. The page directed victims to copy, paste, and run a command on their own systems. That is the defining ClickFix pattern: instead of exploiting a software vulnerability, the attacker persuades the victim to execute the malicious command with the user’s own permissions. 20
25
Fake verification pages are especially effective because they borrow familiar browser and security branding. Research on similar campaigns describes verification buttons or instructions that quietly place a command on the clipboard and then guide the victim through keyboard shortcuts or an operating-system prompt. 26
28
The practical lesson is simple: a CAPTCHA should never require a user to open a shell, PowerShell, Terminal, or Run dialog and execute copied text.
Each package generally received about 50–300 weekly downloads before removal, according to OX Security. 2 Those figures describe registry activity, not the total number of people who may have encountered the phishing pages through direct links or mirror URLs.
That makes ordinary package-download metrics an incomplete measure of the campaign’s intended reach. The packages functioned as a network of hosted landing pages, while the attackers could distribute the URLs through phishing messages, compromised websites, or other channels. 2
17
The npm campaign is best understood as an infrastructure variation on a broader ClickFix model. Across reported campaigns, attackers combine a familiar lure—such as a CAPTCHA, browser error, fake update, or software utility—with instructions that persuade victims to run a command themselves. Proofpoint described the technique as a growing method for delivering malware, while Microsoft has documented related evolutions that use disruption and social engineering to increase the chance of execution. 22
25
27
The supplied evidence does not establish that the 24-package campaign was operated by the same actor behind PavinLoader, EtherHiding, Amatera Stealer, fake OpenAI Codex pages targeting Mac developers, ACR Stealer, or the alleged earlier Beamglea operation. Those examples may illustrate the broader convergence around user-assisted execution, but they should not be treated as confirmed parts of the OX Security campaign without additional evidence.
This case expands the definition of an npm supply-chain threat. A package does not need to run malicious code during installation to become useful to an attacker. A static HTML file, hosted through a trusted registry and its mirrors, can provide the front door for a phishing operation.
For developers and security teams, the key controls are to inspect unexpected npm and CDN URLs, treat fake verification instructions as social engineering, monitor browsers and endpoints for suspicious command execution, and avoid running commands copied from webpages. The most important warning sign is not the CAPTCHA itself—it is any request to bypass normal security behavior by pasting and executing text.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
OX Security identified 24 npm packages carrying the same fake Cloudflare CAPTCHA HTML file.
OX Security identified 24 npm packages carrying the same fake Cloudflare CAPTCHA HTML file. The pages redirected visitors through changing attacker controlled services, including a typosquatted Microsoft login domain and the KeyVal public key value store, before presenting a ClickFix lure that asked victims...
The findings fit the broader rise of ClickFix social engineering, but the supplied evidence does not prove that this npm campaign shared an operator with other named ClickFix operations.