Logo
npm

clickfix_npm_delivery@1.0.2

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC

Malicious

OSV ID

MAL-2026-17692

Ecosystem

npm

Summary

The package has no library surface. package.json declares main: index.html and the tarball ships only that HTML page, whose sole purpose is a ClickFix social-engineering lure. The page impersonates Cloudflare Turnstile (Cloudflare branding, a spoofed dash.cloudflare.com header, a fake 'Verify you are human' checkbox, and a fake 'Ray ID / 403 Forbidden' bot-detection screen). When the victim clicks the fake checkbox, the page silently writes a PowerShell one-liner to the clipboard and instructs the victim to press Win+R, paste, and hit Enter. The clipboard payload uses Start-BitsTransfer to download a script from http://ec2-65-2-4-62.ap-south-1.compute.amazonaws.com:443/script over plain HTTP into $env:temp\sys.ps1 and executes it via iex (gc $t -Raw), giving the operator of that EC2 host arbitrary code execution on the victim's Windows machine. The package name (clickfix_npm_delivery) and description ('Delivery POC Package') identify npm itself as the distribution channel for the lure.

Source: amazon-inspector (f795362044848bcb73d95317e8761c4315720d6a052c6c88fdab47065499510d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.