Toggle light / dark theme

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.

The technique was previously spotted in July by security researcher inf0stache, who found a ‘china_airlines’ npm package that used a fake Cloudflare verification page to redirect visitors to a malicious domain, and was also reported by IntelFusions.

In a later report, OX Security discovered 24 npm packages containing the same malicious HTML page hosted on npm and various mirrors.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */