CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

27 Malicious npm Packages Used in Targeted Phishing Campaign

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Cybersecurity researchers have uncovered a sustained spear-phishing campaign that involved publishing 27 malicious npm packages to steal login credentials from sales and commercial personnel at critical infrastructure-adjacent organizations in the U.S. and Allied nations. The campaign, which lasted five months, targeted 25 organizations across manufacturing, industrial automation, plastics, and healthcare sectors. The attackers repurposed npm and package CDNs to host phishing lures that impersonate secure document-sharing portals and Microsoft sign-in pages.

Timeline

  1. 29.12.2025 11:44 1 articles · 23h ago

    27 Malicious npm Packages Used in Targeted Phishing Campaign

    Cybersecurity researchers have uncovered a sustained spear-phishing campaign that involved publishing 27 malicious npm packages to steal login credentials from sales and commercial personnel at critical infrastructure-adjacent organizations in the U.S. and Allied nations. The campaign, which lasted five months, targeted 25 organizations across manufacturing, industrial automation, plastics, and healthcare sectors. The attackers repurposed npm and package CDNs to host phishing lures that impersonate secure document-sharing portals and Microsoft sign-in pages.

    Show sources

Information Snippets