175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign

175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign

Cybersecurity researchers have identified a new phishing campaign using 175 malicious npm packages to harvest credentials from over 135 organizations worldwide. The campaign exploits npm and UNPKG infrastructure to host redirect scripts and HTML payloads, making it difficult to detect. #Beamglea #CredentialHarvesting

Keypoints

  • The campaign involves 175 npm packages used for credential harvesting.
  • Threat actors exploit npm and UNPKG CDN services to host redirect and HTML payloads.
  • The malicious packages create victim-specific phishing pages with pre-filled credentials.
  • The attack leverages legitimate infrastructure to avoid detection and host resilient phishing campaigns.
  • Over 26,000 downloads suggest widespread analysis and distribution of the malicious packages.

Read More: https://thehackernews.com/2025/10/175-malicious-npm-packages-with-26000.html