Threat Actors Use npm and Mirror Sites to Host Phishing Pages and Redirect Users
466/69 Thursday, August 27, 2026 Reports indicate that threat actors have abused the npm package registry and websites that mirror package data as hosting locations for malicious HTML files. These webpages are designed to impersonate Cloudflare CAPTCHA verification pages to deceive visitors and redirect them to attacker-controlled websites. The incident is notable because it differs […]
