24 npm Packages Abuse unpkg CDN to Host Fake Cloudflare CAPTCHA Phishing Pages
What Happened — Researchers identified a campaign that publishes 24 malicious npm packages. Each package contains a single HTML file that, when accessed via the unpkg.com CDN, displays a counterfeit Cloudflare CAPTCHA page designed to harvest credentials. The actors are not targeting developers who install the packages; they use the CDN as free phishing infrastructure to redirect victims to the fake page.
Why It Matters for Compliance & Audit Readiness
- Phishing attacks directly test the effectiveness of SOC 2 Access Control policies and the organization’s security‑awareness program.
- Continuous monitoring of third‑party code repositories and CDN traffic provides audit‑ready evidence that you’re actively managing supply‑chain risk.
- Demonstrating a documented, repeatable security‑awareness training regimen satisfies the SOC 2 Security principle and can be showcased in a Trust Center.
Who Is Affected – Software development firms, SaaS providers, and any enterprise that incorporates npm packages or relies on unpkg/CDN assets for web applications.
Recommended Actions
- Inventory all npm dependencies and flag any that reference unpkg URLs.
- Implement automated scanning of CDN‑served assets for unexpected redirects or HTML content.
- Enforce strict Content‑Security‑Policy (CSP) headers to block unauthorized iframe or script loads.
- Conduct targeted security‑awareness training on phishing detection, especially around fake CAPTCHA prompts.
- Document these controls and evidence collection in your SOC 2 readiness artifacts.
Technical Notes – The malicious packages are benign when installed (no executable code), but the HTML page served via https://unpkg.com/<package>/ mimics Cloudflare’s CAPTCHA UI, capturing entered text. No CVE is associated; the attack leverages legitimate infrastructure (npm registry + unpkg CDN). Source: The Hacker News