Security Infrastructure
Researchers find npm mirrors used to host phishing redirectors
Image: Primary Researchers identified 24 npm packages containing malicious HTML that impersonates Cloudflare verification pages and redirects visitors to attacker-controlled sites.
The packages are not described as infecting developers who install them; instead, registry mirrors can expose the HTML files directly in browsers. OX Security said attackers use the registry and mirrors as storage, while BleepingComputer confirmed one reviewed page still redirected to a domain that could host a fake Microsoft login page.
Some newer pages retrieve encrypted redirect destinations from a key-value service.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire

