Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps
Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

Key points
- Researchers documented 24 packages on npm, the world's largest registry of open-source JavaScript code, being used to host fake Cloudflare CAPTCHA pages.
- Each package contains a single HTML file, harmless to install, but served publicly through unpkg, a free mirror that turns any npm package into a live web page.
- The pages copy the ClickFix trick: they tell the visitor to paste a command into their computer to "prove they are human", which actually runs malware.
- Developers who install the packages are not the target; ordinary web users who land on the pages via phishing links are.
- The abuse points to a gap in how public package mirrors police the content they serve to browsers.
Security researchers have flagged a cluster of 24 packages on npm, the registry most JavaScript developers pull code from, that aren't really software at all. Each one is a single web page, published so attackers can serve it free through a public mirror. We've tracked ClickFix activity across 33 stories in the last 90 days, and this campaign is a notable twist: the malware delivery chain doesn't touch developer infrastructure at all.
The pages imitate Cloudflare's familiar "checking your browser" screen, the one millions of people clear before a site loads. Here it's a lure.
The campaign was first reported by The Hacker News, drawing on supply-chain security researchers tracking the cluster.
What are the packages actually doing?
Nothing, if you install them. The danger is what they show in a browser. Each package contains one HTML file. When that file loads through unpkg.com, a free service that turns any npm package into a live URL, it renders a fake Cloudflare check page.
That page uses a technique called ClickFix. The visitor is told there's a small problem verifying their browser and asked to press Windows key plus R, paste a line of text, and hit Enter. Those keys open the Run box in Windows. The pasted line downloads and executes malware quietly: software designed to steal data or take over the machine.
Visitors think they're solving a CAPTCHA. They're installing an infection by hand.
Why host phishing pages on npm?
Because the economics are hard to beat. Attackers normally buy hosting and a domain, then keep them alive while security firms push for takedowns. Publishing to npm and pointing victims at the unpkg mirror gives them a page served from a reputable address, with a valid TLS certificate, at no cost.
Takedowns are slower too. A package has to be reviewed, pulled from npm, then purged from the mirror. Until that happens, the phishing link in a message keeps working.
Who is at risk?
Ordinary web users, not developers. Installing one of these packages doesn't run any code on a developer's machine. The payload only matters when the HTML file loads in a browser through a link the attacker sends.
If you get a message with a link leading to a Cloudflare-looking check page that asks you to press Windows+R and paste anything, close the tab. A real CAPTCHA never asks you to run a command. Ever.
Common questions
Is npm itself compromised?
No. The registry is working as designed. Attackers are abusing the fact that anyone can publish a package, and that a separate free service (unpkg) will serve any file inside it as a live web page.
What should I do if I already followed the instructions on such a page?
Disconnect the affected computer from the internet, run a full scan with a reputable security tool, and change passwords for important accounts from a different device. If it's a work machine, tell your IT team immediately.



