Bleepingcomputer
Phishing Campaign Exploits npm Mirrors for Malicious Hosting
Article Content
Threat actors are using npm and its mirrors to host phishing redirect pages that impersonate Cloudflare CAPTCHAs. This method was first identified in July 2026, with 24 malicious npm packages discovered by OX Security. Unlike traditional supply-chain attacks, these packages do not infect developers' systems but serve as free storage for phishing pages. The malicious HTML pages redirect users to attacker-controlled domains, such as login.microsofte.live and login.microlive.org. The use of reputable npm mirrors allows attackers to bypass security measures that might block malicious sites. The phishing pages are designed to look legitimate, embedding Cloudflare's CAPTCHA service to deceive users. While some domains have been blacklisted, the packages remain live and can be updated with new malicious links. This approach represents a novel tactic in leveraging legitimate infrastructure for cybercrime.
Key Points: • Attackers exploit npm mirrors to host phishing pages without infecting systems. • 24 malicious npm packages identified, redirecting users to fake login sites. • Phishing pages impersonate Cloudflare CAPTCHAs to bypass security measures.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.