Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

24 npm Packages Abuse unpkg CDN to Host Fake Cloudflare CAPTCHA Phishing Pages

A new phishing campaign leverages 24 npm packages that serve counterfeit Cloudflare CAPTCHA pages via the unpkg CDN, aiming to steal credentials. This highlights the need for robust SOC 2 access‑control policies and continuous security‑awareness training.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
thehackernews.com

24 npm Packages Abuse unpkg CDN to Host Fake Cloudflare CAPTCHA Phishing Pages

What Happened — Researchers identified a campaign that publishes 24 malicious npm packages. Each package contains a single HTML file that, when accessed via the unpkg.com CDN, displays a counterfeit Cloudflare CAPTCHA page designed to harvest credentials. The actors are not targeting developers who install the packages; they use the CDN as free phishing infrastructure to redirect victims to the fake page.

Why It Matters for Compliance & Audit Readiness

  • Phishing attacks directly test the effectiveness of SOC 2 Access Control policies and the organization’s security‑awareness program.
  • Continuous monitoring of third‑party code repositories and CDN traffic provides audit‑ready evidence that you’re actively managing supply‑chain risk.
  • Demonstrating a documented, repeatable security‑awareness training regimen satisfies the SOC 2 Security principle and can be showcased in a Trust Center.

Who Is Affected – Software development firms, SaaS providers, and any enterprise that incorporates npm packages or relies on unpkg/CDN assets for web applications.

Recommended Actions

  • Inventory all npm dependencies and flag any that reference unpkg URLs.
  • Implement automated scanning of CDN‑served assets for unexpected redirects or HTML content.
  • Enforce strict Content‑Security‑Policy (CSP) headers to block unauthorized iframe or script loads.
  • Conduct targeted security‑awareness training on phishing detection, especially around fake CAPTCHA prompts.
  • Document these controls and evidence collection in your SOC 2 readiness artifacts.

Technical Notes – The malicious packages are benign when installed (no executable code), but the HTML page served via https://unpkg.com/<package>/ mimics Cloudflare’s CAPTCHA UI, capturing entered text. No CVE is associated; the attack leverages legitimate infrastructure (npm registry + unpkg CDN). Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →