
24 Malicious npm Packages Abuse Mirror Infrastructure to Host Obfuscated ClickFix Phishing Pages
Cybersecurity researchers have uncovered 24 malicious npm packages that abuse package mirror services to host obfuscated phishing pages. The packages do not infect a device when a developer downloads or installs them. Instead, the campaign turns trusted npm-related infrastructure into a platform for social engineering. OX Research said each package carried the same HTML file […]
The post 24 Malicious npm Packages Abuse Mirror Infrastructure to Host Obfuscated ClickFix Phishing Pages appeared first on Cyber Security News.