A sophisticated spearphishing campaign has been uncovered targeting sales and commercial personnel at critical infrastructure-adjacent organizations, particularly in the United States and allied nations. Threat actors have weaponized the npm registry by publishing at least 27 malicious packages under multiple aliases, using them as a distribution layer for browser-based phishing components. These packages deliver client-side HTML and JavaScript lures that impersonate secure document-sharing workflows and Microsoft sign-in pages, with the intent to harvest credentials from targeted individuals in sectors such as manufacturing, industrial automation, plastics, and healthcare. The operation demonstrates a high degree of victim-specific preparation, including prefilled email addresses and anti-analysis techniques like honeypot fields and interaction gating.
The campaign leverages npm and package CDNs to create durable hosting infrastructure, making detection and takedown more challenging. After victims interact with the phishing flow, their credentials are redirected to attacker-controlled infrastructure, with identifiers embedded in the URL for tracking. Overlap has been observed between domains used in this campaign and previously documented adversary-in-the-middle (AiTM) phishing infrastructure, indicating a possible connection to known threat actor tactics. Security researchers emphasize the need for increased vigilance among organizations with critical infrastructure exposure, especially those with sales teams that may be targeted through such supply chain abuse of open-source ecosystems.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
A follow-up report publicly described the weaponization of npm to target sales teams in critical infrastructure sectors, emphasizing the campaign's likely role as an entry point into sensitive organizations. This report did not add a distinct new incident beyond the previously disclosed campaign.
Socket reported the campaign and malicious npm accounts to npm security, requested account suspension, and notified the 25 targeted organizations with indicators for triage. This marked the first documented defensive response described in the references.
Researchers found embedded domains and URL patterns overlapping with publicly documented Evilginx adversary-in-the-middle redirector behavior. This indicated the operation may have been capable of stealing session cookies or tokens and bypassing MFA, not just harvesting passwords.
Socket Threat Research Team determined the campaign targeted 25 distinct individuals, mainly sales and commercial staff in manufacturing, industrial automation, plastics, and healthcare organizations in the U.S. and allied countries. The activity suggested a highly selective operation aimed at critical-infrastructure-adjacent sectors.
Threat actors uploaded 27 malicious npm packages across six npm publisher aliases to support the phishing campaign. The packages contained hardcoded victim email addresses and phishing components designed to prefill targets' details and redirect them to actor-controlled infrastructure.
A targeted spearphishing operation abusing the npm registry and package CDNs as hosting for browser-based phishing lures was active for at least five months before it was reported. The campaign focused on impersonating secure document-sharing workflows and Microsoft sign-in pages to capture credentials from selected victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.