MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-08-25 · via BleepingComputer

Attackers use npm package mirrors as free hosts for phishing pages

Threat actors are uploading malicious HTML files to npm packages, which are then served from legitimate mirror domains like UNPKG. The pages impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled sites. The technique avoids hosting on malicious infrastructure and can bypass security filters.

Expanded Detail

The campaign exploits the trust placed in developer infrastructure rather than relying on malicious servers. Each package contains only an HTML file and a package.json declaring it as the main file. When mirror platforms such as UNPKG serve these files directly in a browser, the pages appear to originate from reputable domains, potentially slipping past security tools that block known malicious hosts.

The redirect mechanism has evolved over time. Early versions pointed visitors to domains like microcloud[.]homes and login[.]microsofte[.]live, with some ultimately resolving to legitimate Microsoft Outlook. Newer packages use api.keyval.org to store encrypted redirect URLs, letting attackers change destinations remotely without republishing the package. This flexibility means the same hosted page could later direct victims to ClickFix or other phishing schemes.

Context

This technique could lower the barrier for phishing campaigns by giving attackers reliable, reputable hosting that security filters may trust. Individuals encountering these fake CAPTCHA pages may be redirected to credential-harvesting sites, potentially compromising email or other accounts. Because the infrastructure is legitimate, takedown efforts may be slower, and the remote redirect capability means victims could be sent to different scams over time. Organizations relying on URL filtering may need to reassess how they treat content served from developer platforms.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Malicious ads use Bing redirects to deliver fake Claude installers · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers abuse npm mirrors to host phishing redirect pages.” Browse more stories.