LIVE · cybersecurity feed
Live wire
Employee benefits platform Paylogix says hackers stole financial and health dataAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning Repair
phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

zeroday.news ·

Threat actors are leveraging the npm package registry and its mirroring services to host malicious HTML pages, effectively turning these platforms into free web hosting for phishing redirects. This technique, distinct from typical supply-chain attacks that infect developer systems, uses npm as a validated storage mechanism for attacker-controlled content.

The issue was initially identified in July by a security researcher known as inf0stache, who discovered a package named 'china_airlines' that incorporated a fake Cloudflare verification page. This page was designed to redirect users to a malicious domain. Subsequently, security firm OX Security identified 24 additional npm packages containing similar malicious HTML pages hosted across npm and its mirrors.

When these packages are mirrored by services like UNPKG and npmmirror, individual files within them become directly accessible via a browser. For instance, an HTML file can be rendered from a URL such as `https://unpkg[.]com/ndmxchdjxn2@1.0.0/index[.]html`. This allows the malicious HTML to execute from a legitimate domain, potentially bypassing security measures that might block attacker-controlled infrastructure.

The malicious HTML pages are designed to impersonate Cloudflare security verification screens, often embedding the legitimate Cloudflare Turnstile CAPTCHA service. Regardless of the CAPTCHA outcome, the pages execute heavily obfuscated JavaScript to redirect the visitor.

Early versions of these redirects, observed in July, pointed to `microcloud[.]homes`. By August, some redirects were observed leading to `login[.]microsofte[.]live`. In some cases, these initial redirects ultimately resolved to the legitimate Microsoft Outlook mail login site at `https://outlook.office.com/mail`.

Later iterations of the attack adopted a more dynamic redirection method. This newer code retrieves an encrypted value from `api.keyval.org`, a legitimate platform for storing key-value pairs. The encrypted value is then decrypted in the user's browser, and the visitor is redirected to the resulting URL. This mechanism allows attackers to alter the redirect destination remotely without needing to modify or republish the npm package. At the time of OX Security's research, this method was redirecting visitors to the legitimate ChatGPT website.

While the current observed redirects have sometimes led to legitimate sites, the flexibility of this technique means attackers could easily change the destination to phishing pages, malware downloads, or other malicious content. OX Security also noted that npm packages, once published, may persist on mirroring services even after being removed from the official npm registry.

Security researchers advise treating direct HTML requests to npm mirror domains as potentially suspicious. This incident highlights a growing trend of threat actors exploiting legitimate infrastructure for payload storage and data delivery, rather than solely for direct malware distribution.

phishingnation-statecloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]

breach

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber

ai

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

breach

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

nation-state

58 arrested in international cybercrime crackdown

Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.

security

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.