Tuesday 22 September 2026 02:43:52 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#mirror infrastructure


When npm Becomes a Phishing Host: The Mirror Abuse Behind ClickFix Lures

Published: 26 August 2026 10:25Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A cluster of malicious npm packages did not try to run code on install; instead, it appears to have turned package mirrors into a browser-facing trap for social engineering.