Researchers disclosed a campaign using 24 malicious npm packages as phishing infrastructure, abusing package CDN mirrors such as unpkg to publish a single HTML file that renders a fake Cloudflare CAPTCHA page. Instead of targeting developers through dependency compromise or malware-laced code, the packages were designed to exploit the trust and availability of npm mirror services, giving attackers a seemingly legitimate hosting channel for phishing content.
The operation reportedly evolved after an earlier Microsoft-themed typosquatted domain was blocked by Google Chrome Safe Browsing, with the attackers shifting to KeyVal as a dead-drop resolver to control redirection targets. Researchers said the current lure redirects users to the legitimate ChatGPT website, but warned the same infrastructure can be quickly repointed to ClickFix-style phishing pages or malware delivery sites, turning public package mirrors into flexible staging points for social-engineering attacks.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Socket reported in October 2025 that 175 npm packages abused unpkg.com's CDN to host redirect scripts in a campaign dubbed Beamglea. The campaign routed victims to credential-harvesting pages.
OX Security researchers disclosed a cluster of 24 malicious npm packages that abuse npm mirrors such as unpkg to render fake Cloudflare CAPTCHA pages. Rather than targeting developers who install them, the packages were used as free, trusted-looking phishing hosting infrastructure.
After the earlier domain was blocklisted, the actor moved to using api.keyval[.]org as a dead drop resolver. The mirrored HTML pages retrieved and decoded redirect URLs from the public key-value service.
Google Chrome Safe Browsing blocklisted login[.]microsofte[.]live during the campaign. This defensive action forced the threat actor to change tactics.
Early versions of the campaign used the typosquatted domain login[.]microsofte[.]live, which impersonated a Microsoft login page. The malicious npm packages' mirrored HTML pages queried this infrastructure as part of the redirect flow.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourceox.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.