Cybersecurity researchers have revealed details of an “ongoing and targeted” spear-phishing campaign that published over two dozen packages to the npm registry to facilitate credential theft. The activity involved the upload of 27 npm packages from six different npm aliases, primarily targeting vendors and commercial personnel at organizations involved in critical infrastructure in the U.S. and allied countries, according to Socket.
See also: Malicious npm package evades AI security tools

“A five-month operation turned 27 npm packages into resilient hosting for browser-based decoys that mimicked Microsoft document sharing and login portals, targeting 25 organizations in the manufacturing, industrial automation, plastics, and healthcare sectors for credential theft,” researchers Nicholas Anderson and Kirill Boychenko.
Instead of requiring users to install the packages, the campaign aims to repurpose npm and the packages’ content delivery networks (CDNs) as hosting infrastructure, using them to deliver HTML and JavaScript baits that mimic secure document sharing and are embedded directly into phishing pages. Victims are then redirected to Microsoft login pages with their email address pre-populated in the form.
Using package CDNs offers several benefits, including the ability to turn a legitimate distribution service into a takedown-resistant infrastructure. It also allows attackers to easily switch to other publisher aliases and package names, even if the libraries are removed.
See also: Shai-Hulud v2 campaign expands from npm to Maven

The packages incorporate various client-side controls to challenge analysis attempts, including filtering bots, avoiding sandboxes, and requiring mouse or touch input before leading victims to a credential collection infrastructure controlled by the attackers.
JavaScript code is obfuscated or heavily minified to complicate automated inspection. Another critical anti-analysis check used by the attacker involves honeypot form fields that are hidden from real users but likely filled in by crawlers.
This acts as a second layer of defense, preventing the attack from going any further. Socket noted that the domains packaged in these packages overlap with adversary-in-the-middle (AitM) associated with Evilginx, an open-source phishing kit. This is not the first time that npm has been turned into a phishing infrastructure. In October 2025, a campaign called Beamglea saw unknown attackers upload 175 malicious packages for credential harvesting attacks.
See also: New version of Shai-Hulud worm spreads via npm, GitHub

It is currently unknown how the attackers obtained the email addresses. However, given that many of the targeted companies are concentrated at major international trade fairs, such as Interpack and K-Fair, it is suspected that the attackers may have collected the information from these websites and combined it with general online recognition.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
