
CYBERSECURITY
FEATURED ANALYSIS
Phishing Campaign Leveraging the NPM Ecosystem
SOURCE
Blog RSS Feed | Snyk
DATE
READ
1 min read
A new phishing campaign weaponizes NPM and the unpkg CDN. Over 175 throwaway packages are used to host scripts that redirect users to credential-harvesting sites. The attack targets enterprise employees through the …
A new phishing campaign weaponizes NPM and the unpkg CDN. Over 175 throwaway packages are used to host scripts that redirect users to credential-harvesting sites. The attack targets enterprise employees through the browser, not developers at install time.