Attackers use npm package mirrors as free hosts for phishing pages
Threat actors are uploading malicious HTML files to npm packages, which are then served from legitimate mirror domains like UNPKG. The pages impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled sites. The technique avoids hosting on malicious infrastructure and can bypass security filters.
This summary is AI-generated and original to Mobble; the linked article is the authoritative source.
Original headline: “Hackers abuse npm mirrors to host phishing redirect pages.” Browse more stories.