Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.
Packagist packages hid malicious package.json scripts, enabling Linux binary execution during installs and workflows.