Hackers abuse npm mirrors to host phishing redirect pages
Executive Summary
Threat actors exploit npm and its mirrors to host malicious HTML pages that mimic Cloudflare CAPTCHAs, redirecting visitors to attacker-controlled sites.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-25T21:39:01+00:00 - Category: threat-intel
Original Description: Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
"To study and not think is a waste. To think and not study is dangerous."
— Confucius
Source: Bleeping Computer