Hackers abuse npm mirrors to host phishing redirect pages
ID: 8562b092-83c4-5502-a30f-4feaf6f2ddd4
STIX ID: report--8562b092-83c4-5502-a30f-4feaf6f2ddd4
Feed Name: Bleeping Computer
Researchers discovered threat actors abusing npm packages and public npm mirrors to host malicious HTML pages that mimic Cloudflare verification (including embedded Turnstile CAPTCHA) and execute obfuscated JavaScript to redirect visitors to attacker-controlled domains; attackers use the registry and mirror URLs as trusted hosting for phishing pages and can remotely change redirect targets via services like api.keyval.org, potentially enabling credential theft or further malicious redirects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
