Malicious npm Packages: 24 Host Phishing Pages
ID: baaa1a15-387d-5929-8f2d-997779eb266a
STIX ID: report--baaa1a15-387d-5929-8f2d-997779eb266a
Feed Name: CyberNexora News
OX Security identified 24 npm packages that contained the same malicious HTML page designed to impersonate a Cloudflare verification screen; by relying on legitimate npm mirrors (unpkg, npmmirror, yarn) the attacker used trusted domains to host phishing pages and redirect victims, risking credential theft or ClickFix-style command execution even though installing the packages did not execute malware. The report details the attack chain, observed indicators such as login.microsofte.live, recommended monitoring of direct .html requests to mirror domains, and mitigation guidance for detection and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
