Cybersecurity researchers have identified a new phishing campaign using 175 malicious npm packages to harvest credentials from over 135 organizations worldwide. The campaign exploits npm and UNPKG infrastructure to host redirect scripts and HTML payloads, making it difficult to detect. #Beamglea #CredentialHarvesting
Keypoints
- The campaign involves 175 npm packages used for credential harvesting.
- Threat actors exploit npm and UNPKG CDN services to host redirect and HTML payloads.
- The malicious packages create victim-specific phishing pages with pre-filled credentials.
- The attack leverages legitimate infrastructure to avoid detection and host resilient phishing campaigns.
- Over 26,000 downloads suggest widespread analysis and distribution of the malicious packages.
Read More: https://thehackernews.com/2025/10/175-malicious-npm-packages-with-26000.html