Mobble
Technology · Cybersecurity · published 2026-08-25 · via BleepingComputer

Attackers use npm package mirrors as free hosts for phishing pages

Threat actors are uploading malicious HTML files to npm packages, which are then served from legitimate mirror domains like UNPKG. The pages impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled sites. The technique avoids hosting on malicious infrastructure and can bypass security filters.

Read the full article at BleepingComputer →
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Hackers abuse npm mirrors to host phishing redirect pages.” Browse more stories.