Attackers use npm package mirrors as free hosts for phishing pages
Threat actors are uploading malicious HTML files to npm packages, which are then served from legitimate mirror domains like UNPKG. The pages impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled sites. The technique avoids hosting on malicious infrastructure and can bypass security filters.
The campaign exploits the trust placed in developer infrastructure rather than relying on malicious servers. Each package contains only an HTML file and a package.json declaring it as the main file. When mirror platforms such as UNPKG serve these files directly in a browser, the pages appear to originate from reputable domains, potentially slipping past security tools that block known malicious hosts.
The redirect mechanism has evolved over time. Early versions pointed visitors to domains like microcloud[.]homes and login[.]microsofte[.]live, with some ultimately resolving to legitimate Microsoft Outlook. Newer packages use api.keyval.org to store encrypted redirect URLs, letting attackers change destinations remotely without republishing the package. This flexibility means the same hosted page could later direct victims to ClickFix or other phishing schemes.
This technique could lower the barrier for phishing campaigns by giving attackers reliable, reputable hosting that security filters may trust. Individuals encountering these fake CAPTCHA pages may be redirected to credential-harvesting sites, potentially compromising email or other accounts. Because the infrastructure is legitimate, takedown efforts may be slower, and the remote redirect capability means victims could be sent to different scams over time. Organizations relying on URL filtering may need to reassess how they treat content served from developer platforms.