27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials Emmie Evans December 29, 2025

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

Cybersecurity researchers have disclosed details of what has been described as a “sustained and targeted” spear-phishing campaign that has published over two dozen packages to the npm registry to facilitate credential theft.
The activity, which involved uploading 27 npm packages from six different npm aliases, has primarily targeted sales and commercial personnel at critical

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top