Hackers abuse npm mirrors to host phishing redirect pages
-
Threat actors are now abusing the npm ecosystem and its mirror registries to host malicious HTML pages designed to impersonate Cloudflare CAPTCHA challenges. These pages serve as redirects, funneling unsuspecting visitors to attacker-controlled websites.
The attack leverages the trust associated with legitimate package registries. By publishing packages that contain these deceptive HTML files, the actors ensure the malicious content is hosted on reputable infrastructure, which can help bypass security filters and increase the likelihood of user engagement.
Once a user lands on the page, they are presented with a fake Cloudflare verification prompt. Instead of a legitimate security check, interacting with the page triggers a redirect to a phishing site or other malicious destination.
- The abuse involves npm and its public mirrors.
- The payload is an HTML page mimicking a Cloudflare CAPTCHA.
- The primary function of the page is to redirect visitors to external, attacker-controlled URLs.
This technique highlights an ongoing trend of attackers abusing trusted, high-reputation services for phishing infrastructure. Organizations should monitor for unexpected npm packages and review any content hosted on mirror domains that attempts to impersonate common security prompts.
Source: BleepingComputer
Has your team implemented monitoring for malicious or suspicious packages published to internal or public npm mirrors?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login