ClickFix Phishing Campaign Exploits npm Registry Mirrors
Score: 7/10

ClickFix Phishing Campaign Exploits npm Registry Mirrors

Threat actors associated with the Beamglea campaign are abusing the npm registry and unpkg mirrors to host malicious HTML files that simulate Cloudflare CAPTCHA pages to distribute ClickFix phishing malware.

Executive Summary

A sophisticated phishing campaign, identified as Beamglea, is exploiting the trust associated with npm registry mirrors like unpkg.com to host fake Cloudflare CAPTCHA pages. Researchers discovered 24 malicious npm packages designed not to infect the local developer environment, but to provide a persistent and 'validated' hosting platform for malicious HTML files. These files are rendered directly by public CDNs, lending legitimacy to the phishing infrastructure.

The attack chain involves redirecting users to these mirrored HTML pages, which then use obfuscated JavaScript to communicate with a remote server. Initially, the actors used typosquatted Microsoft domains (login[.]microsofte[. ]live) but transitioned to using api.keyval[. ]org as a dead drop resolver (DDR) once their primary domains were blacklisted. This transition highlights the adversary's agility in bypassing browser-based security protections like Google Safe Browsing.

This campaign represents a significant shift in supply chain abuse where the registry is used as a free, high-reputation storage and distribution network rather than a direct code execution vector. Because mirrors often persist even after a package is removed from the main npm registry, these phishing pages can remain live indefinitely, posing a long-term risk to organizations whose users may encounter these links.

Key Details

Threat Name

ClickFix Phishing via npm Mirrors

Affects

npm registry, unpkg, npmmirror, yarn, tencent

Adversary

Beamglea

Malware/Tools

ClickFix, Beamglea

Report Score

7out of 10
Quality Score
Good
IOC Quality8
TTP Details8
Detection Guidance5
Enterprise Relevance8
Clarity & Structure9
Technical Depth7

Sources