Hackers abuse npm mirrors to host phishing redirect pages

Executive Summary

Threat actors exploit npm and its mirrors to host malicious HTML pages that mimic Cloudflare CAPTCHAs, redirecting visitors to attacker-controlled sites.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-25T21:39:01+00:00 - Category: threat-intel

Original Description: Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

"To study and not think is a waste. To think and not study is dangerous."

— Confucius
Source: Bleeping Computer