Attackers Host Phishing Pages via npm Packages Without Installation
TechNadu · x · 2026-08-26
OX Security discovered that attackers have found a new use for npm packages: hosting phishing pages. They found 24 malicious packages containing malicious HTML that could be automatically mirrored and rendered through trusted domains like unpkg. The danger of this technique lies in the fact that users do not even need to install these packages; simply visiting the generated links can expose them to phishing attacks.
More from Safety
- Bill Gates: Humanity has crossed AI danger thresholds, policy is top priority — peterwildeford · 2026-08-26
- Bill Gates: AI era among the most turbulent in history, would back a plan to slow it — peterwildeford · 2026-08-26
- Saviynt launches Zuma to secure AI agents and non-human identities — shauntrennery · 2026-08-26
- Meta settles with states for up to $16.68B, far below trillion-dollar talk — RihardJarc · 2026-08-26
- AI patient assessment ignores trust and safety: Study — EricTopol · 2026-08-26
- AI forecaster Kokotajlo joins Palisade podcast to discuss Plan A and agent deception case — DKokotajlo · 2026-08-26