HomeSecurity27 malicious npm packages are used as Phishing infrastructure

27 malicious npm packages used as Phishing infrastructure

Cybersecurity researchers have revealed details of an “ongoing and targeted” spear-phishing campaign that published over two dozen packages to the npm registry to facilitate credential theft. The activity involved the upload of 27 npm packages from six different npm aliases, primarily targeting vendors and commercial personnel at organizations involved in critical infrastructure in the U.S. and allied countries, according to Socket.

See also: Malicious npm package evades AI security tools

npm

“A five-month operation turned 27 npm packages into resilient hosting for browser-based decoys that mimicked Microsoft document sharing and login portals, targeting 25 organizations in the manufacturing, industrial automation, plastics, and healthcare sectors for credential theft,” researchers Nicholas Anderson and Kirill Boychenko.

Instead of requiring users to install the packages, the campaign aims to repurpose npm and the packages’ content delivery networks (CDNs) as hosting infrastructure, using them to deliver HTML and JavaScript baits that mimic secure document sharing and are embedded directly into phishing pages. Victims are then redirected to Microsoft login pages with their email address pre-populated in the form.

Using package CDNs offers several benefits, including the ability to turn a legitimate distribution service into a takedown-resistant infrastructure. It also allows attackers to easily switch to other publisher aliases and package names, even if the libraries are removed.

See also: Shai-Hulud v2 campaign expands from npm to Maven

27 malicious npm packages used as Phishing infrastructure

The packages incorporate various client-side controls to challenge analysis attempts, including filtering bots, avoiding sandboxes, and requiring mouse or touch input before leading victims to a credential collection infrastructure controlled by the attackers.

JavaScript code is obfuscated or heavily minified to complicate automated inspection. Another critical anti-analysis check used by the attacker involves honeypot form fields that are hidden from real users but likely filled in by crawlers.

This acts as a second layer of defense, preventing the attack from going any further. Socket noted that the domains packaged in these packages overlap with adversary-in-the-middle (AitM) associated with Evilginx, an open-source phishing kit. This is not the first time that npm has been turned into a phishing infrastructure. In October 2025, a campaign called Beamglea saw unknown attackers upload 175 malicious packages for credential harvesting attacks.

See also: New version of Shai-Hulud worm spreads via npm, GitHub

27 malicious npm packages used as Phishing infrastructure

It is currently unknown how the attackers obtained the email addresses. However, given that many of the targeted companies are concentrated at major international trade fairs, such as Interpack and K-Fair, it is suspected that the attackers may have collected the information from these websites and combined it with general online recognition.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS