Phishing Campaign Exploits npm Mirrors for Malicious Hosting

Phishing Campaign Exploits npm Mirrors for Malicious Hosting

First seen 25 Aug 2026, 22:22 UTC CybernewsBleepingcomputerwww.ox.security 62.2

Article Content

Browse articles
ThreatCluster

Threat actors are using npm and its mirrors to host phishing redirect pages that impersonate Cloudflare CAPTCHAs. This method was first identified in July 2026, with 24 malicious npm packages discovered by OX Security. Unlike traditional supply-chain attacks, these packages do not infect developers' systems but serve as free storage for phishing pages. The malicious HTML pages redirect users to attacker-controlled domains, such as login.microsofte.live and login.microlive.org. The use of reputable npm mirrors allows attackers to bypass security measures that might block malicious sites. The phishing pages are designed to look legitimate, embedding Cloudflare's CAPTCHA service to deceive users. While some domains have been blacklisted, the packages remain live and can be updated with new malicious links. This approach represents a novel tactic in leveraging legitimate infrastructure for cybercrime.

Key Points: • Attackers exploit npm mirrors to host phishing pages without infecting systems. • 24 malicious npm packages identified, redirecting users to fake login sites. • Phishing pages impersonate Cloudflare CAPTCHAs to bypass security measures.

Timeline

2026-07-01
First malicious npm package identified
Security researcher inf0stache discovered a 'china_airlines' npm package hosting a fake Cloudflare verification page.
BleepingComputer
2026-08-01
24 malicious packages reported
OX Security flagged 24 npm packages containing malicious HTML pages, marking a significant phishing campaign.
Cybernews
2026-08-25
Current status of phishing campaign
Phishing pages remain live on npm mirrors, with attackers able to update links and deploy new scams.
BleepingComputer