Executive Summary
A sophisticated phishing campaign, identified as Beamglea, is exploiting the trust associated with npm registry mirrors like unpkg.com to host fake Cloudflare CAPTCHA pages. Researchers discovered 24 malicious npm packages designed not to infect the local developer environment, but to provide a persistent and 'validated' hosting platform for malicious HTML files. These files are rendered directly by public CDNs, lending legitimacy to the phishing infrastructure.
The attack chain involves redirecting users to these mirrored HTML pages, which then use obfuscated JavaScript to communicate with a remote server. Initially, the actors used typosquatted Microsoft domains (login[.]microsofte[. ]live) but transitioned to using api.keyval[. ]org as a dead drop resolver (DDR) once their primary domains were blacklisted. This transition highlights the adversary's agility in bypassing browser-based security protections like Google Safe Browsing.
This campaign represents a significant shift in supply chain abuse where the registry is used as a free, high-reputation storage and distribution network rather than a direct code execution vector. Because mirrors often persist even after a package is removed from the main npm registry, these phishing pages can remain live indefinitely, posing a long-term risk to organizations whose users may encounter these links.
