27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

Details of a “sustained and targeted” spear-phishing attack that published more than two dozen packages to the npm registry to enable credential theft have been made public by cybersecurity researchers.

According to Socket, the activity, which included uploading 27 npm packages from six distinct npm aliases, has mostly targeted sales and commercial staff at critical infrastructure-adjacent firms in the United States and Allied countries.

Researchers Nicholas Anderson and Kirill Boychenko reported that a five-month operation transformed 27 npm packages into robust hosting for browser-run lures that imitate Microsoft sign-in and document-sharing portals, targeting 25 companies in the manufacturing, industrial automation, plastics, and healthcare sectors for credential theft.

The names of the packages are listed below –

  • adril7123
  • ardril712
  • arrdril712
  • androidvoues
  • assetslush
  • axerification
  • erification

The campaign’s ultimate objective is to use npm and package content delivery networks (CDNs) as hosting infrastructure instead of requiring users to install the packages read more about 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *