# Researchers find npm mirrors used to host phishing redirectors

_Tuesday, August 25, 2026 at 5:39 PM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Researchers find npm mirrors used to host phishing redirectors — Primary](https://www.bleepstatic.com/content/hl-images/2026/05/15/npm.jpg)

Researchers identified 24 npm packages containing malicious HTML that impersonates Cloudflare verification pages and redirects visitors to attacker-controlled sites.

The packages are not described as infecting developers who install them; instead, registry mirrors can expose the HTML files directly in browsers. OX Security said attackers use the registry and mirrors as storage, while BleepingComputer confirmed one reviewed page still redirected to a domain that could host a fake Microsoft login page.

Some newer pages retrieve encrypted redirect destinations from a key-value service.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/)

---
Canonical: https://techandbusiness.org/newswire/d9tkG5KaVEeWsBt2J6vN80
Retrieved: 2026-08-26T01:15:50.999Z
Publisher: Tech & Business (techandbusiness.org)
