Npm registry spear-phishing campaign targeting sales personnel
Campaign
Summary
Hide ▲
Show ▼
Unknown threat actors ran a five-month spear-phishing campaign that abused 27 npm packages as browser-hosting infrastructure, turning a software registry into a resilient credential-theft delivery channel. The operation targeted 25 organizations and sales and commercial personnel across multiple sectors in the U.S. and Allied nations, making the login-harvesting effort broader and more durable than a one-off phishing page.
Related Happenings
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor Meta
H score31
First: 15.06.2026 22:32
Last: 15.06.2026 22:32
Sources 1
About this happening:
North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor MetaAbout this happening: North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
Contagious Interview UNK_DeadDrop GitHub phishing campaign
Campaign
H score37
First: 15.06.2026 22:32
Last: 15.06.2026 22:32
Sources 1
About this happening:
The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...
Contagious Interview UNK_DeadDrop GitHub phishing campaign
CampaignAbout this happening: The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...
Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack
Incident
H score13
First: 01.06.2026 20:40
Last: 01.06.2026 20:40
Sources 1
About this happening:
Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...
Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack
IncidentAbout this happening: Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...
Timeline
-
29.12.2025 11:44 2 articles · 6mo ago
npm package phishing campaign disclosure
Initial DisclosureUnknown threat actors ran a five-month npm phishing campaign that uploaded 27 packages from six aliases and used npm/package CDN-hosted HTML and JavaScript lures to impersonate document-sharing portals and Microsoft sign-in, targeting 25 organizations and sales and commercial personnel across manufacturing, industrial automation, plastics, and healthcare in the U.S. and Allied nations for credential theft; the packages also used bot filtering, sandbox evasion, mouse-or-touch checks, honeypot fields, and overlap with Evilginx-associated adversary-in-the-middle infrastructure.
Show sources
- 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials — thehackernews.com — 29.12.2025 11:44
- 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials — thehackernews.com — 29.12.2025 11:44