logo

Malicious npm Packages: 24 Host Phishing Pages

ID: baaa1a15-387d-5929-8f2d-997779eb266a

STIX ID: report--baaa1a15-387d-5929-8f2d-997779eb266a

Feed Name: CyberNexora News

Threat Score
60/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Debolina Barik

...
...

OX Security identified 24 npm packages that contained the same malicious HTML page designed to impersonate a Cloudflare verification screen; by relying on legitimate npm mirrors (unpkg, npmmirror, yarn) the attacker used trusted domains to host phishing pages and redirect victims, risking credential theft or ClickFix-style command execution even though installing the packages did not execute malware. The report details the attack chain, observed indicators such as login.microsofte.live, recommended monitoring of direct .html requests to mirror domains, and mitigation guidance for detection and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.