Hackers Abuse npm Mirrors to Host Phishing Redirect Pages
Malicious HTML pages impersonating Cloudflare CAPTCHAs distributed via npm registry mirrors

Key Takeaways
- Threat actors are abusing npm mirrors to host phishing pages impersonating Cloudflare CAPTCHAs.
- Visitors are redirected to attacker-controlled websites following fake CAPTCHA interactions.
- The abuse reflects broader supply chain risks within the npm ecosystem and its mirror network.
- No patch is currently available; mitigation focuses on source verification and user caution.
Quick answers
- What happened?
- Threat actors have been observed abusing npm and its mirrors to host malicious HTML pages that mimic Cloudflare CAPTCHAs. These pages are designed to redirect visitors to attacker-controlled websites, potentially facilitating credential theft or malware installation. The abuse of trusted package mirrors highlights the ongoing risk of supply chain manipulation in the developer ecosystem.
- Which products are affected?
- npm registry
- What should defenders do?
- Verify the integrity of npm package sources and mirrors. Exercise caution when encountering unexpected CAPTCHA prompts, particularly those originating from package installation or documentation pages. Monitor security advisories from npm and Cloudflare for updates.
According to a report by BleepingComputer, threat actors are exploiting npm and its mirror infrastructure to host malicious HTML pages. These pages impersonate Cloudflare CAPTCHAs to trick visitors into interacting with fake verification prompts. The interaction is designed to redirect the user to an attacker-controlled website, the destination of which may be used for phishing or further malware distribution. The exact method by which the malicious pages were uploaded to npm mirrors is not detailed in the report, but the incident underscores the risks associated with relying on third-party package mirrors. Both npm and Cloudflare are mentioned in the report, though the nature of their involvement—whether as targets, intermediaries, or unrelated parties—is not specified. No specific victim counts or threat actor identities have been disclosed. As of the report date, no patch has been issued, and the npm registry remains the primary product referenced in the advisory.
Security Details
Malicious HTML pages hosted on npm mirrors mimic Cloudflare CAPTCHA interfaces. User interaction triggers redirection to attacker-controlled domains, potentially resulting in credential compromise or malware installation.
Affected products
npm registry
Mitigation
Verify the integrity of npm package sources and mirrors. Exercise caution when encountering unexpected CAPTCHA prompts, particularly those originating from package installation or documentation pages. Monitor security advisories from npm and Cloudflare for updates.
Sources
BleepingComputer
Hackers abuse npm mirrors to host phishing redirect pages
Aug 25, 2026 · 21:39
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




