logo

Hackers abuse npm mirrors to host phishing redirect pages

ID: 8562b092-83c4-5502-a30f-4feaf6f2ddd4

STIX ID: report--8562b092-83c4-5502-a30f-4feaf6f2ddd4

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Lawrence Abrams

...
...

Researchers discovered threat actors abusing npm packages and public npm mirrors to host malicious HTML pages that mimic Cloudflare verification (including embedded Turnstile CAPTCHA) and execute obfuscated JavaScript to redirect visitors to attacker-controlled domains; attackers use the registry and mirror URLs as trusted hosting for phishing pages and can remotely change redirect targets via services like api.keyval.org, potentially enabling credential theft or further malicious redirects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.