Attackers Used 27 Malicious npm Packages to Host Phishing Pages and Steal Login Credentials
Cybersecurity researchers have uncovered a phishing campaign that abused the npm package registry to steal login credentials. The operation involved 27 malicious npm packages created specifically for phishing purposes. These packages were not designed to provide useful code to developers. Instead, they were used as hosting infrastructure for credential-stealing pages. The campaign remained active for … Continued