Attackers abuse npm and UNPKG to host phishing redirect pages
OX Security found 24 npm packages that contain only malicious HTML impersonating a Cloudflare Turnstile check. UNPKG copied the files, so opening the HTML from the trusted mirror can redirect a visitor.






