ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Threat actors abuse npm and mirrors like UNPKG and npmmirror to host malicious HTML pages impersonating Cloudflare CAPTCHAs, redirecting visitors to attacker-controlled sites. OX Security found 24 such packages. The pages embed Cloudflare's legitimate Turnstile service and execute obfuscated JavaScript to redirect regardless of verification outcome.
Tap to vote and see what everyone thinks.
Summary by ByteBrief