Phishing Campaign Leveraging the NPM Ecosystem
CYBERSECURITY FEATURED ANALYSIS

Phishing Campaign Leveraging the NPM Ecosystem

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

A new phishing campaign weaponizes NPM and the unpkg CDN. Over 175 throwaway packages are used to host scripts that redirect users to credential-harvesting sites. The attack targets enterprise employees through the …

A new phishing campaign weaponizes NPM and the unpkg CDN. Over 175 throwaway packages are used to host scripts that redirect users to credential-harvesting sites. The attack targets enterprise employees through the browser, not developers at install time.