Campaigns
npm/unpkg Fake Cloudflare CAPTCHA ClickFix Phishing Campaign

npm/unpkg Fake Cloudflare CAPTCHA ClickFix Phishing Campaign

ClickFixFakeCaptchanpmunpkgnpmmirror
A threat actor is using the npm registry and its mirrors as free, trusted hosting for fake Cloudflare CAPTCHA pages that funnel victims into ClickFix social engineering. OX Security found 24 packages carrying a single index.html lure that redirects visitors to attacker infrastructure; none run code at install time, and developers are not the target. After Chrome flagged the original Microsoft typosquat, the actor switched to api.keyval.org as a dead drop resolver, swapping destinations without republishing.

Indicators of Compromise

api.keyval.org
login.microsofte.live

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION

DETECTION


Technique ID

Technique Name

Detection Strategy

T1566

Phishing

Unusual inbound email activity where attachments or embedded URLs are delivered to users followed by execution of new processes or suspicious document behavior. Detection involves correlating email metadata, file creation, and network activity after a phishing message is received. Monitor for malicious payload delivery through phishing where attachments or URLs in email clients (e.g., Thunderbird, mutt) result in unusual file creation or outbound network connections. Focus on correlation between mail logs, file writes, and execution activity.

T1566.002

Spearphishing Link

Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity. Detection of spearphishing links through mail logs and browser activity. Behavior includes email with suspicious URLs → user click recorded in mail/web proxy logs → shell or interpreter launched from browser process.

T1204

User Execution

Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage. Cause→effect chain: (1) User app/browser/archiver logs an open/click or abnormal exit, (2) new executable/script/archive extracted into $HOME/Downloads, /tmp, or ~/.cache, (3) parent app spawns shell/interpreter (bash/sh/python/node/curl/wget) or desktop file, and (4) new outbound connection(s)...

T1204.001

Malicious Link

Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs. Behavioral chain: (1) browser/office/GUI mail client opens a URL, (2) outbound connection to untrusted domain, (3) a new file is saved in $HOME/Downloads, /tmp, or cache immediately after.

T1204.004

Malicious Copy and Paste

A user is socially engineered (web page, email, document) to open Run/PowerShell/CMD and paste an obfuscated one-liner. The chain is: (1) user context active in a browser/email/office app → (2) process creation of a command interpreter with suspicious arguments (base64/Invoke-Expression/web download/pipeline to shell) → (3) optional file drop in %TEMP% or %APPDATA% → (4) outbound network connection to an external domain. Events are correlated within a short window and with consistent user/session. User pastes a multi-line or one-liner into a terminal (bash/zsh) that downloads/decodes and executes content. Chain: terminal exec of curl/wget/bash/sh with pipe to interpreter or base64-decode...

T1059.001

PowerShell

Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations.

T1059.003

Windows Command Shell

Detects interactive or scripted abuse of cmd.exe, batch files, or shell invocation chains. Focuses on parent-child relationships (e.g., cmd.exe launched from unusual parents), anomalous command-line parameters, and chaining with discovery, credential access, or lateral movement behaviors.

T1218.005

Mshta

Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.

T1218.011

Rundll32

Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta).

T1102

Web Service

Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence. Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context.

T1102.001

Dead Drop Resolver

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior). Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

T1583.001

Domains

Monitor logged domain name system (DNS) data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. Domain registration information is, by design, captured in public registration logs. Consider use of services that may aid in tracking of newly acquired domains, such as WHOIS databases and/or passive DNS. In some cases it may be possible to pivot on known pieces of domain registration information to uncover other infrastructure purchased by the adversary. Consider...

T1584.006

Web Services

Once adversaries leverage the abused web service as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control [Web Service](https://attack.mitre.org/techniques/T1102) or [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567) .

T1608.001

Upload Malware

If infrastructure or patterns in malware have been previously identified, internet scanning may uncover when an adversary has staged malware to make it accessible for targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle, such as [User Execution](https://attack.mitre.org/techniques/T1204) or [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105) .

T1608.005

Link Target

If infrastructure or patterns in malicious web content have been previously identified, internet scanning may uncover when an adversary has staged web content to make it accessible for targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as during [Spearphishing Link](https://attack.mitre.org/techniques/T1598/003) , [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002) , or [Malicious Link](https://attack.mitre.org/techniques/T1204/001) .

T1036

Masquerading

Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage. Adversary drops renamed binaries in uncommon directories (e.g., /tmp, /dev/shm) or uses special characters in names (e.g., trailing space, Unicode RLO). Execution or cronjob registration follows shortly after file drop.

T1027

Obfuscated Files or Information

Correlates script execution or suspicious parent processes with creation or modification of encoded, compressed, or encrypted file formats (e.g., .zip, .7z, .enc) and abnormal command-line syntax or PowerShell obfuscation. Detects use of gzip, base64, tar, or openssl in scripts or commands that encode/encrypt files after file staging or system enumeration.

T1140

Deobfuscate/Decode Files or Information

An adversary leverages built-in tools such as certutil.exe, powershell.exe, or copy.exe to decode, reassemble, or extract hidden malicious content from obfuscated containers or encoded formats. The decoding utility often spawns shortly after file staging or download and may be chained with script interpreters or further payload execution. The adversary uses native utilities like base64, gzip, tar, or openssl to decode, decompress, or decrypt files that were previously staged or downloaded. These tools may be chained with curl/wget and executed via bash/zsh, often to extract an embedded payload or reverse shell script.

Observed Countries250

AD (337)
AE (716)
AF (284)
AG (206)
AI (443)
AL (113)
AM (928)
AO (398)
AQ (710)
AR (84)
AS (623)
AT (492)
AU (672)
AW (744)
AX (714)
AZ (182)
BA (30)
BB (276)
BD (37)
BE (199)
BF (623)
BG (32)
BH (143)
BI (409)
BJ (734)
BL (578)
BM (144)
BN (532)
BO (243)
BQ (818)
BR (798)
BS (520)
BT (595)
BV (466)
BW (691)
BY (375)
BZ (162)
CA (842)
CC (324)
CD (142)
CF (743)
CG (227)
CH (347)
CI (300)
CK (476)
CL (280)
CM (507)
CN (408)
CO (511)
CR (512)
CU (397)
CV (651)
CW (935)
CX (502)
CY (600)
CZ (25)
DE (789)
DJ (13)
DK (803)
DM (772)
DO (825)
DZ (327)
EC (65)
EE (978)
EG (699)
EH (119)
ER (106)
ES (428)
ET (128)
FI (457)
FJ (333)
FK (29)
FM (682)
FO (702)
FR (20)
GA (527)
GB (486)
GD (105)
GE (353)
GF (906)
GG (428)
GH (367)
GI (872)
GL (78)
GM (845)
GN (587)
GP (720)
GQ (212)
GR (435)
GS (380)
GT (221)
GU (762)
GW (662)
GY (520)
HK (515)
HM (52)
HN (432)
HR (844)
HT (199)
HU (493)
ID (564)
IE (8)
IL (359)
IM (502)
IN (588)
IO (168)
IQ (829)
IR (786)
IS (912)
IT (883)
JE (330)
JM (706)
JO (855)
JP (577)
KE (218)
KG (858)
KH (887)
KI (596)
KM (21)
KN (153)
KP (531)
KR (27)
KW (191)
KY (901)
KZ (292)
LA (395)
LB (761)
LC (532)
LI (127)
LK (675)
LR (261)
LS (549)
LT (633)
LU (972)
LV (78)
LY (25)
MA (810)
MC (650)
MD (411)
ME (590)
MF (208)
MG (220)
MH (552)
MK (376)
ML (63)
MM (472)
MN (367)
MO (586)
MP (711)
MQ (57)
MR (289)
MS (68)
MT (594)
MU (417)
MV (469)
MW (297)
MX (932)
MY (592)
MZ (186)
NA (108)
NC (724)
NE (902)
NF (922)
NG (805)
NI (763)
NL (195)
NO (992)
NP (757)
NR (486)
NU (5)
NZ (42)
OM (268)
PA (277)
PE (366)
PF (427)
PG (311)
PH (565)
PK (753)
PL (740)
PM (131)
PN (373)
PR (622)
PS (652)
PT (700)
PW (64)
PY (575)
QA (189)
RE (410)
RO (881)
RS (587)
RU (867)
RW (138)
SA (933)
SB (885)
SC (463)
SD (50)
SE (53)
SG (489)
SH (922)
SI (507)
SJ (201)
SK (496)
SL (282)
SM (199)
SN (376)
SO (712)
SR (766)
SS (584)
ST (404)
SV (495)
SX (883)
SY (633)
SZ (109)
TC (545)
TD (324)
TF (723)
TG (97)
TH (176)
TJ (466)
TK (949)
TL (657)
TM (261)
TN (231)
TO (71)
TR (693)
TT (975)
TV (417)
TW (342)
TZ (464)
UA (916)
UG (91)
UM (517)
US (59)
UY (913)
UZ (842)
VA (778)
VC (649)
VE (781)
VG (204)
VI (439)
VN (164)
VU (740)
WF (93)
WS (979)
XK (626)
YE (172)
YT (255)
ZA (121)
ZM (228)
ZW (728)