npm mirrors are becoming an unexpected vehicle for phishing, as attackers host malicious HTML pages on them that mimic Cloudflare checks and redirect visitors to their own sites. The SecNews technical team explains how it works and what to watch out for.

The activity was captured by OX Security and examined in a report by BleepingComputer. According to the findings, the perpetrators are leveraging the npm registry as free storage, while the pages are automatically copied from services such as UNPKG and npmmirror.
See also: RedC2 packages on npm install backdoor on Linux
How to use npm mirrors
npm is best known as a package repository for JavaScript applications. However, a package can also contain a simple index.html. When a mirror allows individual files to be directly displayed in the browser, its legitimate domain essentially acts as free hosting for a page that would not be easily hosted on the attackers' infrastructure.
OX Security detected 24 packages with the same malicious HTML page, which appeared on both npm and different mirroring services. In one case, the package contained only the index.html and package.json files, with the latter declaring HTML as the main file.
A similar technique was discovered in July in the china_airlines by researcher inf0stache. The page appeared under a trusted domain, making the origin appear less suspicious to users and automated filters.
The critical point is not only the presence of a suspicious package in the dependency list. Even a link to a specific file can trigger the mechanism. Using known infrastructure creates a layer of trust, because the browser and filters initially see a domain associated with software development, and not an obviously malicious website.

Cloudflare's deceptive verification
The HTML page is presented as a Cloudflare security check and incorporates the legitimate Turnstile. The visual similarity may create the impression that the visitor simply needs to complete a routine verification before continuing.
However, there is heavily obfuscated JavaScript running in the background. The redirect can occur either after verification or regardless of the result. In older versions, visitors were directed to microcloud.homes, while newer variants used login.microsofte.live, targeting a possible fake Microsoft login page.
OX Security also observed the use of api.keyval.org, a legitimate key-value storage service. The code retrieves an encrypted value, decrypts it in the browser, and uses the result as the destination. This allows attackers to change the URL without republishing the package.
See also: Malicious arrayref version infects Rust projects at compile time

What development teams should watch out for
The installation of these packages was not reported as a process that infects a developer's computer on its own. The risk arises when someone directly opens the malicious HTML or follows the redirect, which can lead to phishing, malware downloads, or ClickFix-like techniques.

Security teams should be wary of HTML files loaded directly from npm mirrors, especially when they mimic Cloudflare CAPTCHAs and contain unreadable JavaScript. They should also check external requests, new packages, and redirects, not just the domain shown in the address bar.
Removing a package from the official npm registry does not necessarily mean it disappears from every mirror at the same time. For this, developers should review lockfiles, dependencies, and internal directories, while safe browsing mechanisms should also evaluate the content of the page.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: StubMaker: 16 malicious RubyGems packages steal data
The case shows that trust in a legitimate domain is not enough to qualify a file as safe. npm mirrors offer useful infrastructure for development, but direct HTML hosting and redirects require increased scrutiny from developers and cybersecurity teams.
