Credential Phishing Campaign Using 175 Malicious npm Packages
Summary
Hide ▲
Show ▼
A credential phishing campaign, codenamed Beamglea, has targeted over 135 industrial, technology, and energy companies worldwide. The campaign utilized 175 malicious npm packages, collectively downloaded 26,000 times, to host redirect scripts that lead victims to credential harvesting pages. The packages exploit npm's public registry and UNPKG's CDN to distribute HTML payloads designed to capture Microsoft credentials. The campaign leverages legitimate infrastructure to create a resilient phishing operation that is difficult to detect and mitigate. The packages do not execute malicious code upon installation, making them harder to identify. The HTML files, disguised as legitimate documents, redirect victims to phishing sites that pre-fill email fields, increasing the likelihood of successful credential theft.
Timeline
-
10.10.2025 13:45 1 articles · 5d ago
175 Malicious npm Packages Used in Credential Phishing Campaign
A credential phishing campaign, codenamed Beamglea, has been identified using 175 malicious npm packages. These packages, downloaded 26,000 times, exploit npm's public registry and UNPKG's CDN to host redirect scripts that lead victims to credential harvesting pages. The campaign targets over 135 companies in industrial, technology, and energy sectors. The packages do not execute malicious code upon installation, making them harder to detect. The HTML files, disguised as legitimate documents, redirect victims to phishing sites that pre-fill email fields, increasing the likelihood of successful credential theft.
Show sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
Information Snippets
-
The Beamglea campaign targeted over 135 companies in industrial, technology, and energy sectors.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
175 malicious npm packages were used, collectively downloaded 26,000 times.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
The packages use npm's public registry and UNPKG's CDN to host redirect scripts.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
The campaign does not execute malicious code upon package installation.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
HTML files masquerade as purchase orders, technical specifications, or project documents.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
The JavaScript file 'beamglea.js' redirects victims to Microsoft credential harvesting pages.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
The phishing pages pre-fill the email field to increase the attack's success rate.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
The campaign leverages legitimate infrastructure to create a resilient phishing operation.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45
-
The packages were published across 9 accounts, with automated victim-specific HTML generation.
First reported: 10.10.2025 13:451 source, 1 articleShow sources
- 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign — thehackernews.com — 10.10.2025 13:45