Cybersecurity researchers have identified a sophisticated phishing campaign, codenamed Beamglea, that leverages 175 malicious packages published on the npm registry to facilitate credential harvesting attacks. The campaign has targeted over 135 organizations across industrial, technology, and energy sectors worldwide. The malicious packages, which have been collectively downloaded more than 26,000 times, serve as infrastructure rather than directly infecting systems upon installation. Instead of executing malicious code during installation, these packages are designed to exploit npm’s public registry and the unpkg.com CDN to host and distribute redirect scripts. These scripts are embedded in HTML files that masquerade as legitimate documents such as purchase orders or technical specifications. When opened, the HTML files load JavaScript from the unpkg CDN, which then redirects victims to credential harvesting pages, often targeting Microsoft account credentials. The packages are programmatically generated using a Python script named 'redirect_generator.py', which creates packages with randomized names like 'redirect-xxxxxx', injects the victim’s email address, and a custom phishing URL. This automation allows the threat actors to rapidly scale their infrastructure and personalize attacks. The campaign was initially flagged by Paul McCarty at Safety in late September 2025, and further expanded upon by Socket’s Threat Research Team, who discovered additional packages and provided a comprehensive analysis. The download counts for these packages are believed to be inflated by automated scanners, security researchers, and CDN infrastructure, rather than widespread accidental installation by developers. The threat actors’ abuse of trusted infrastructure like npm and unpkg.com makes detection and mitigation more challenging, as these services are widely used and considered reputable within the software development community. At the time of reporting, most of the malicious packages remained live, prompting researchers to petition for their removal and the suspension of the associated threat actor accounts. The campaign’s use of randomized package names and the lack of direct malicious payloads in the packages themselves further complicate traditional detection methods. The operation’s codename, Beamglea, appears to be unique to this campaign, with no prior online presence, aiding in tracking and attribution. Researchers have identified over 630 HTML files associated with the campaign, each crafted to lure victims into providing sensitive credentials. The campaign highlights the growing trend of abusing open-source package registries and CDNs as free, scalable infrastructure for phishing operations. Security teams are advised to monitor for suspicious npm packages and scrutinize the use of unpkg.com-hosted scripts in their environments. The incident underscores the importance of supply chain vigilance and the need for enhanced monitoring of public code repositories for abuse.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting described the activity as the Beamglea campaign and said the attackers abused both the npm ecosystem and the unpkg CDN to support large-scale credential phishing operations. This added attribution and technical context to the previously disclosed package-based phishing activity.
Security researchers identified 175 malicious npm packages that were being used to host phishing infrastructure, with reporting indicating the campaign targeted more than 135 organizations. The packages were also reported to have accumulated roughly 26,000 downloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.