Tag

Malicious Software

All articles tagged with #malicious software

Malicious npm Packages Exploit Phishing to Steal Login Credentials

Originally Published 13 days ago — by The Hacker News

Featured image for Malicious npm Packages Exploit Phishing to Steal Login Credentials
Source: The Hacker News

Cybersecurity researchers uncovered a targeted spear-phishing campaign using 27 malicious npm packages to host browser-based phishing lures mimicking document-sharing portals and Microsoft sign-in pages, primarily targeting organizations in critical infrastructure sectors across multiple countries. The campaign leverages package CDNs for resilient hosting, employs anti-analysis techniques, and hard-codes specific email addresses, with the goal of stealing login credentials. The activity highlights ongoing threats in the software supply chain, emphasizing the need for stringent dependency verification and monitoring.