Aikido.Dev
Phishing Campaign Utilizes Malicious npm Packages Targeting Various Sectors
First seen 23 Jan 2026, 22:10 UTC
•


•74% similarity
•20.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A new phishing campaign has emerged, utilizing malicious npm packages to target employees in industrial, energy, and healthcare sectors across Europe, the Middle East, and the United States. Attackers have published multiple versions of these packages, including flockiali, opresc, prndn, oprnm, and operni, which serve custom credential harvesting pages. This sophisticated approach leverages trusted software repositories to deliver phishing infrastructure.
ThreatCluster AI
How this analysis works