Affected Systems

24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly.

Exploitation Status

Active campaign. Malicious packages were live on npm and unpkg mirrors. Threat actors actively adapted tactics after initial C2 domain (login.microsofte.live) was blocklisted, switching to KeyVal API as dead drop resolver. Some packages remain available for download as of publication.

Business Impact

Threat actors exploit npm registry and CDN mirrors as free, trusted hosting for phishing pages that mimic Cloudflare CAPTCHA verification. Victims clicking links to unpkg-hosted HTML files are redirected through ClickFix-style social engineering to attacker-controlled infrastructure. Current payload redirects to legitimate ChatGPT site but can be weaponized for credential theft or malware delivery. Risk is to end users, not developer environments. Demonstrates infrastructure abuse pattern where legitimate services provide persistence even after takedown from official registry.

Urgency

🟡 Within a week

Recommended Actions

  • Block or monitor access to known malicious npm package URLs on unpkg.com and other npm mirrors listed in the campaign (24 packages identified including bgzxcuite2, prezdentkxheiw, egair0810, mnteckets, airdzticket, egypt0811, passport811, and 17 others)
  • Implement web filtering or DNS blocking for typosquat domains associated with the campaign, specifically login.microsofte.live and monitor for similar Microsoft impersonation domains
  • Review proxy and web gateway logs for connections to unpkg.com serving HTML files from suspicious npm packages, particularly those with random or low-reputation package names
  • Educate users on ClickFix-style phishing tactics involving fake CAPTCHA verification pages, especially those appearing on otherwise trusted domains like unpkg.com
  • Monitor for abuse of dead drop resolver services like KeyVal (api.keyval.org) in web traffic, which may indicate redirection infrastructure for phishing campaigns