Hackers hide fake security check pages inside trusted software libraries to trick users and steal password logins.
Cybersecurity researchers have issued an urgent warning after discovering that malicious hackers are hiding fake verification pages inside trusted online software libraries.
Scammers are uploading dozens of empty software packages containing fake security check pages to open source software registries like npm.
When everyday internet users click on these links, they see what looks like a normal security check asking them to solve a puzzle or click a button to prove they are human.
However, the deceptive page silently redirects visitors to dangerous external websites designed to steal private user passwords, account logins, or secret personal details.
The dangerous technology warning was formally published in online security reports on August 26, 2026, after security researchers at OX Security uncovered the sneaky scheme.
Cyber analysts tracked at least twenty-four distinct software packages designed purely to serve as staging points for fake web pages.
The attack operates globally, reaching developers, office workers, and everyday internet users across North America, Europe, Asia, and Africa.
Because these fake web pages are hosted on reputable, trusted software servers, standard security tools and web browsers often fail to flag them as harmful.
The main reason this sneaky scam is succeeding is that hackers are taking advantage of automatic backup servers called mirrors.
When a programmer uploads a file to a public software library, other trusted server networks automatically copy and host those files globally.
Even if main security teams catch the fake package and delete it from the primary library, the mirrored copies remain online on trusted web domains.
Hackers then send these mirror web addresses directly to targets, exploiting the public’s natural trust in recognized web domains to trick people into dropping their guard.
See Also: Hackers Use Fake Student Resumes to Secretly Install Malware on Researchers’ Computers
Explaining how cybercriminals are using trusted developer software systems to host fake web pages rather than traditional virus files, cybersecurity analyst Tushar Subhra Dutta reported that “the campaign does not infect a developer by installing a package,” adding that “instead, it exploits the confidence users place in familiar hosting domains to make a phishing page appear safer than it is”.
Detailing how deceptive verification screens trick everyday users into visiting malicious websites, Tushar Subhra Dutta noted that “the malicious HTML presents a fake Cloudflare CAPTCHA and includes scrambled JavaScript,” warning that “this creates an indirect attack path, where the registry ecosystem becomes the delivery channel rather than the malware execution point”.
Warning that removing the original bad software file does not completely fix the security threat, research analysts at OX Security emphasized that “a removed package may remain available through mirrors,” noting that “researchers warned that the destination could change to a ClickFix page or another phishing lure, without changing the mirrored package file”.
By exposing how bad actors hide fake security pages on trusted software servers, security experts are helping internet users stay safe.
Doublec hecking full website addresses, avoiding unexpected verification links, and keeping computer software updated ensures that personal account logins and private records remain safe from sneaky online thieves.

