Security researchers have uncovered a campaign involving 24 malicious npm packages that use legitimate package-mirroring services to deliver phishing content.
The attackers are not primarily interested in getting developers to install the packages. Instead, they are using the packages as a place to store deceptive web pages. Because those pages can be accessed through well-known package-hosting domains, the links may appear more trustworthy to unsuspecting users.
The campaign was discovered by OX Security, which found that the affected packages contained similar HTML-based phishing content. Some of the packages were receiving hundreds of downloads each week before they were taken down.
Trusted Domains Used to Build Trust
The malicious packages include HTML files designed to resemble familiar security verification pages, including fake Cloudflare CAPTCHA screens.
When someone opens one of these files through a package mirror, hidden JavaScript can communicate with external infrastructure controlled by the attackers. The visitor can then be sent to another website chosen by the attackers.
This approach gives criminals an advantage: the initial link may point to a legitimate package-mirror domain rather than a newly created suspicious website.
Services such as unpkg and other npm mirrors are commonly used by developers, making them difficult to block across an organization.
The destination can also be changed later, meaning the same hosted file could potentially be used to send visitors to different phishing campaigns.
ClickFix Makes the Attack More Dangerous
The campaign is particularly concerning because it can be connected to the growing ClickFix attack technique.
ClickFix campaigns typically show victims a fake verification message and instruct them to perform an action, such as copying a command and running it on their computer. Instead of exploiting a technical vulnerability, the attacker relies on the victim to complete the dangerous step.
Security teams should therefore watch for unusual activity involving package mirrors, especially when employees are accessing HTML files directly rather than downloading normal development dependencies.
Developers should also be careful with package links received through emails, messages, tickets, or search results. A familiar domain does not guarantee that every file hosted on it is safe.
Most importantly, never run a command simply because a webpage claims it is required to complete a CAPTCHA, security check, or verification process.
This campaign demonstrates how attackers are finding creative ways to hide phishing infrastructure inside services that organizations already trust.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | login[.]microsofte[.]live | Typosquatted Microsoft domain used by the earlier campaign version |
| Domain | api[.]keyval[.]org | Legitimate key-value service abused to retrieve encrypted redirect data |
| URL | https://unpkg[.]com/ndmxchdjxn2@1.0.0/index.html | Direct mirror-hosted malicious HTML page |
| Encoded value | PpihAtpV1i29jeS3Skk7XU74X2Zkd5wyzF2DOzY77k1Fz7GNvGafkxVGs+z6VOGy6E43n+JQgKSUsn+S5NjXlBmcq4= | Encrypted value retrieved through the remote logic |
| Malicious npm package | bgzxcuite2 | Microsoft typosquat family, taken down |
| Malicious npm package | prezdentkxheiw | Microsoft typosquat family, taken down |
| Malicious npm package | egair0810 | Microsoft typosquat family, taken down |
| Malicious npm package | mnteckets | Microsoft typosquat family, taken down |
| Malicious npm package | airdzticket | Microsoft typosquat family, taken down |
| Malicious npm package | egypt0811 | Microsoft typosquat family, taken down |
| Malicious npm package | passport811 | Microsoft typosquat family, taken down |
| Malicious npm package | vxhjkseuiaqkb | Microsoft typosquat family |
| Malicious npm package | ndmushdkeqe | Microsoft typosquat family |
| Malicious npm package | ndmxchdjxn2 | Microsoft typosquat family |
| Malicious npm package | ndmfguyhoxc3 | Microsoft typosquat family |
| Malicious npm package | mjsdqwocvn | Microsoft typosquat family |
| Malicious npm package | m2fcsfyjkuxb | Microsoft typosquat family |
| Malicious npm package | m3fdfocdoewn | Microsoft typosquat family |
| Malicious npm package | @worrisome/reutil | keyval new-logic family |
| Malicious npm package | testdgdbcsd | Microsoft typosquat family |
| Malicious npm package | tesgfvbncsdbcv | Microsoft typosquat family |
| Malicious npm package | mndsxcusiwlk1 | keyval new-logic family |
| Malicious npm package | mn2adskhweox | keyval new-logic family |
| Malicious npm package | mn3sadkoiewu | keyval new-logic family |
| Malicious npm package | mn4xcouzvhus | keyval new-logic family |
| Malicious npm package | mbxcnsuwgs1 | keyval new-logic family |
| Malicious npm package | skxcmwuncbg2 | keyval new-logic family |
| Malicious npm package | mobiwaefhxc3 | keyval new-logic family |