Skip to content
DnsLister Forum

Where domain hunters compare notes

Hackers abuse npm mirrors to host phishing redirect pages

This is a clever abuse of a trusted package registry. Threat actors are uploading malicious HTML pages to npm and its mirrors (like the npmmirror.com CDN) that impersonate Cloudflare CAPTCHA challenges. When a user visits the page, it tricks them into performing a "Verify You Are Human" action, which then redirects the victim to attacker-controlled phishing sites.

Technical Breakdown: – TTP: Abuse of Trusted Services (TTP: T1583.006 – Acquire Infrastructure: Web Services). The attackers are leveraging npm’s CDN infrastructure to host the phishing landing pages, bypassing reputation-based blocklists. – IOCs: The malicious packages are hosted on npm under various names. The redirects point to attacker-controlled domains. Specific package names and redirect URLs are not yet widely published, but the technique relies on the npmmirror.com domain being whitelisted by security tools. – Affected Systems: Any user or system that visits a URL hosted on an npm mirror CDN. The attack is not limited to developers; it targets anyone who clicks a link pointing to the malicious npm-hosted page.

Defense: – URL Inspection: Do not blindly trust URLs from CDNs or package registries. Inspect the full URL path for suspicious HTML file names. – Web Filtering: Block or flag .html files hosted on package registry CDNs unless explicitly required. – User Awareness: Train users to recognize that legitimate CAPTCHAs do not redirect to external domains after verification.

Source: https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *