Hackers abuse npm mirrors to host phishing redirect pages

Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm packages and mirrors like UNPKG and npmmirror to host malicious HTML pages that impersonate Cloudflare CAPTCHAs and redirect users to attacker-controlled destinations. The campaign uses legitimate infrastructure as free hosting for phishing pages, with some redirects pointing to Microsoft login themes, ChatGPT, or dynamically controlled URLs. #Cloudflare #npm #UNPKG #npmmirror #Turnstile

Keypoints

  • Attackers hide malicious HTML inside npm packages and mirrors.
  • The pages impersonate Cloudflare verification screens with Turnstile CAPTCHA.
  • Opening mirrored files in a browser serves the content from legitimate domains.
  • Redirect targets have included Microsoft and ChatGPT-themed destinations.
  • Researchers advise treating direct HTML access on npm mirrors as suspicious.

Read More: https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/