Skip to main content
Back to Newswire
Security Infrastructure

Researchers find npm mirrors used to host phishing redirectors

Researchers find npm mirrors used to host phishing redirectors Image: Primary
Researchers identified 24 npm packages containing malicious HTML that impersonates Cloudflare verification pages and redirects visitors to attacker-controlled sites. The packages are not described as infecting developers who install them; instead, registry mirrors can expose the HTML files directly in browsers. OX Security said attackers use the registry and mirrors as storage, while BleepingComputer confirmed one reviewed page still redirected to a domain that could host a fake Microsoft login page. Some newer pages retrieve encrypted redirect destinations from a key-value service.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire