logo

Using StackBlitz to Launch Phishing Campaigns

ID: 35d6e2f8-55b7-5ae4-9d8a-e44ad46adf1f

STIX ID: report--35d6e2f8-55b7-5ae4-9d8a-e44ad46adf1f

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz observed multiple active phishing campaigns that host credential-harvesting pages on StackBlitz by abusing its preboot/CachedFetch functionality to deliver server-side pages as JSON and redirect victims to fake login portals (Outlook, OneDrive/Office365, Gmail, Yahoo, etc.). The report documents two spam delivery methods (OneDrive-themed lures), shows traffic and source code analysis, and lists many StackBlitz subdomains and additional malicious domains as IOCs to aid detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.