Hackers abuse NPM mirrors to host phishing redirect pages

Hackers abuse NPM mirrors to host phishing redirect pages

npm

Threat actors abuse npm and its mirrors to host malicious HTML pages that masquerade as Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.

The technology was discovered by security researchers in July infostachewho found an NPM package “china_airlines” that used a fake Cloudflare verification page to redirect visitors to a malicious domain, also reported by IntelFusions.

In a later report, OX Security discovered 24 npm packages containing the same malicious HTML page hosted on npm and various mirrors.

Picture

However, unlike the typical NPM supply chain attacks we’ve seen recently, installing the packages will not infect a developer’s computer with malware or infostealers.

Instead, attackers use the npm registry as free storage for malicious HTML pages, which are then copied by mirror platforms such as UNPKG and npmmirror.

Because some of these platforms allow individual files in NPM packages to be accessed directly in a browser, they effectively turn these developer sites into free web hosting for phishing sites.

“While the malware is simply a single HTML page within the npm package and downloading it would cause no harm, the threat actor’s use of npm is not to infect developers who install it, but rather to use the registry and its mirrors as a safe, validated storage for the malware,” explains OX security.

BleepingComputer examined one of the packages identified in the campaign and found that it contained only two files, an index.html page and a package.json file that declared the HTML file to be the main file of the package.

npm package that contains an index.html and a package.json file
npm package that contains an index.html and a package.json file
Source: BleepingComputer

When UNPKG mirrors the package, the HTML file can be opened directly in a browser using a URL such as https://unpkg(.)com/ndmxchdjxn2@1.0.0/index(.)html.

This causes the attacker’s HTML to be rendered in the browser by the legitimate unpkg.com domain rather than the infrastructure controlled by the threat actor, potentially bypassing security software that may have blocked a malicious website.

OX says this technique effectively turns NPM mirrors into “free front-end hosts for malicious HTML pages and potentially other payloads as well.”

Malicious HTML code acts as a redirector

The malicious HTML code spoofs a Cloudflare security verification page that embeds Cloudflare’s legitimate Turnstile CAPTCHA service.

Malicious HTML page was loaded by UNPKG
Malicious HTML page was loaded by UNPKG
Source: BleepingComputer

Regardless of whether the verification is successful, the page executes heavily obfuscated JavaScript that redirects the visitor to another website.

OX Security research team leader Moshe Siman Tov Bustan told BleepingComputer that previous versions were redirected to Microcloud(.)homes in July and to login(.)microsofte(.)live in August. Researchers said some of the earliest redirects in July ultimately led to the legitimate Microsoft Outlook email login page (https://outlook.office.com/mail).

BleepingComputer tested one of the malicious pages hosted through UNPKG and confirmed that visitors are still being redirected to this domain.

This domain is currently not active, but can be used to host a fake Microsoft login page.

The researchers say other packages switched to a different redirection method that uses api.keyval.org, a legitimate platform for storing key-value pairs.

According to the researchers, the newer code retrieves an encrypted value from the service, decrypts it in the browser, and then redirects the visitor to the decrypted URL.

This allows attackers to remotely change the redirect URL without modifying or republishing the npm package. At the time of OX’s research, the remotely configured target redirected visitors to the legitimate ChatGPT website.

While OX says the value could be changed at any time to point to ClickFix or other phishing pages, the npm-hosted HTML code reviewed by BleepingComputer does not perform a ClickFix attack.

These pages could also redirect visitors to phishing pages, malware downloads, or other attacker-controlled destinations.

OX also warns that npm packages may remain on mirrors after they are removed from the official npm registry.

“Threat actors continue to find and exploit new and novel techniques, not only to spread malware, but also to exploit legitimate infrastructure to store their payloads and data,” OX concluded.

The researchers recommend treating direct HTML requests to NPM mirror domains as potentially suspicious.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *