[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fle_Px-2lH72YSRB4YCkBsuZQfEqtyW2GUqPv0Thkr6w":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"2f4d45c9-3933-43a2-a1d8-d25b5e8ae2e7","malicious-npm-packages-abuse-cdn-infrastructure-to-host-phishing-pages","6a163481-6f76-4b8b-8da4-fc70cb1ee4e5","Malicious npm Packages Abuse CDN Infrastructure to Host Phishing Pages","Attackers published 24 npm packages that exploit unpkg, a legitimate CDN mirror for npm content, to host convincing fake Cloudflare CAPTCHA and Microsoft login phishing pages — effectively laundering malicious content through a trusted, validated delivery channel. This technique is particularly dangerous because developers and security tools may implicitly trust traffic originating from unpkg.com, bypassing reputation-based defenses. The use of KeyVal as a dead drop resolver adds a layer of indirection that makes payload delivery harder to detect and block. This campaign highlights how open, permissive package registries and CDN ecosystems can be weaponized against end users even when developers themselves are not directly compromised.","**Immediate actions:**\n- Audit all npm dependencies in active projects against the 24 known malicious package names and remove any matches immediately.\n- Block or restrict unpkg.com and similar CDN mirrors at the network perimeter if they are not explicitly required by business operations.\n- Report the malicious packages to npm Security and request expedited takedown.\n\n**Long-term improvements:**\n- Enforce a vetted, internal npm registry proxy (e.g., Verdaccio, Artifactory) so all packages are reviewed before reaching production environments.\n- Implement software composition analysis (SCA) tools in CI\u002FCD pipelines to flag newly published or suspicious transitive dependencies.\n- Establish a formal third-party package approval policy requiring provenance verification before any new package is added to codebases.\n\n**Detection measures:**\n- Monitor DNS and HTTP traffic for requests to known dead drop resolver services such as KeyVal and alert on unexpected outbound connections to CDN-hosted HTML resources.\n- Deploy endpoint and browser telemetry to detect CAPTCHA-style redirect chains that funnel users to credential-harvesting pages.\n- Subscribe to threat intelligence feeds covering malicious npm packages to receive early warnings of newly identified supply chain threats.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST CSF DE.CM-3: Personnel activity monitoring","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","SLSA Supply Chain Levels for Software Artifacts (provenance verification)","OWASP A06:2021 – Vulnerable and Outdated Components","GDPR Article 32: Security of Processing (where EU user credentials are harvested)","published","2026-08-25T14:21:27.225452+00:00","2026-08-25T14:21:26.92+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002F24-npm-packages-abuse-unpkg-mirrors-to.html","24-npm-packages-abuse-unpkg-mirrors-to-host-fake-cloudflare-captcha-pages-56d961","24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]