<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers abuse npm mirrors to host phishing redirect pages]]></title><description><![CDATA[<p dir="auto">Threat actors are now abusing the npm ecosystem and its mirror registries to host malicious HTML pages designed to impersonate Cloudflare CAPTCHA challenges. These pages serve as redirects, funneling unsuspecting visitors to attacker-controlled websites.</p>
<p dir="auto">The attack leverages the trust associated with legitimate package registries. By publishing packages that contain these deceptive HTML files, the actors ensure the malicious content is hosted on reputable infrastructure, which can help bypass security filters and increase the likelihood of user engagement.</p>
<p dir="auto">Once a user lands on the page, they are presented with a fake Cloudflare verification prompt. Instead of a legitimate security check, interacting with the page triggers a redirect to a phishing site or other malicious destination.</p>
<ul>
<li>The abuse involves npm and its public mirrors.</li>
<li>The payload is an HTML page mimicking a Cloudflare CAPTCHA.</li>
<li>The primary function of the page is to redirect visitors to external, attacker-controlled URLs.</li>
</ul>
<p dir="auto">This technique highlights an ongoing trend of attackers abusing trusted, high-reputation services for phishing infrastructure. Organizations should monitor for unexpected npm packages and review any content hosted on mirror domains that attempts to impersonate common security prompts.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Has your team implemented monitoring for malicious or suspicious packages published to internal or public npm mirrors?</p>
]]></description><link>https://xploitlk.com/topic/101/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:29:08 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/101.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 26 Aug 2026 00:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>