24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages

Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing pages. The campaign does not infect a developer by installing a package. Instead, it exploits the confidence users place in familiar hosting domains to make a phishing page appear safer than it is. The packages contain a […]

This article has been indexed from Cyber Security News

Read the original article: