Find notable cyber news and cases, enriched with sources, timelines, and signals.

Npm registry spear-phishing campaign targeting sales personnel

Campaign
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

Unknown threat actors ran a five-month spear-phishing campaign that abused 27 npm packages as browser-hosting infrastructure, turning a software registry into a resilient credential-theft delivery channel. The operation targeted 25 organizations and sales and commercial personnel across multiple sectors in the U.S. and Allied nations, making the login-harvesting effort broader and more durable than a one-off phishing page.

Related Happenings

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale

Threat Actor Meta
H score31 First: 15.06.2026 22:32 Last: 15.06.2026 22:32 Sources 1

About this happening: North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...

Contagious Interview UNK_DeadDrop GitHub phishing campaign

Campaign
H score37 First: 15.06.2026 22:32 Last: 15.06.2026 22:32 Sources 1

About this happening: The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...

Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack

Incident
H score13 First: 01.06.2026 20:40 Last: 01.06.2026 20:40 Sources 1

About this happening: Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...

Timeline

  1. 29.12.2025 11:44 2 articles · 6mo ago

    npm package phishing campaign disclosure

    Initial Disclosure

    Unknown threat actors ran a five-month npm phishing campaign that uploaded 27 packages from six aliases and used npm/package CDN-hosted HTML and JavaScript lures to impersonate document-sharing portals and Microsoft sign-in, targeting 25 organizations and sales and commercial personnel across manufacturing, industrial automation, plastics, and healthcare in the U.S. and Allied nations for credential theft; the packages also used bot filtering, sandbox evasion, mouse-or-touch checks, honeypot fields, and overlap with Evilginx-associated adversary-in-the-middle infrastructure.

    Show sources