Attackers Turn npm Mirrors Into Phishing Launchpads
Security researchers have found threat actors publishing packages to npm that contain fake CAPTCHA verification pages designed to look like Cloudflare's bot-check screens. Because these packages get pulled into public npm mirrors, the malicious HTML ends up hosted on trusted-looking infrastructure, giving phishing links a veneer of legitimacy and helping them slip past spam filters and blocklists.
Visitors who land on these pages, often via links in emails or malicious ads, see what looks like a routine "verify you're human" check before being silently redirected to attacker-controlled sites pushing scams, credential theft, or malware downloads.
npm has reportedly been removing the offending packages as they're identified, but the mirror ecosystem means copies can persist or resurface across other package registries and CDNs that sync from npm.