Attackers Host Phishing Pages via npm Packages Without Installation

TechNadu · x · 2026-08-26

OX Security discovered that attackers have found a new use for npm packages: hosting phishing pages. They found 24 malicious packages containing malicious HTML that could be automatically mirrored and rendered through trusted domains like unpkg. The danger of this technique lies in the fact that users do not even need to install these packages; simply visiting the generated links can expose them to phishing attacks.

Original post →

More from Safety

Safety channel →