cloudphishing

Hackers abuse npm mirrors to host phishing redirect pages

August 26, 2026

Back to all posts

Source: BleepingComputer

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.
cloudphishing

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment