Cybersecurity researchers have revealed a “sustained and targeted” spear-phishing campaign involving the publication of 27 malicious packages on the npm registry, aimed at credential theft. This operation utilized six different npm aliases to target sales and commercial personnel within critical sectors. The attackers’ strategy emphasizes the need for vigilance against such threats in software development environments. Users are urged to remain cautious and monitor for any suspicious activity related to these packages.
Want More Context? 🔎






