Aikido.Dev Phishing Campaign Utilizes Malicious npm Packages Targeting Various Sectors
Article Content
Browse articles
A new phishing campaign has emerged, utilizing malicious npm packages to target employees in industrial, energy, and healthcare sectors across Europe, the Middle East, and the United States. Attackers have published multiple versions of these packages, including flockiali, opresc, prndn, oprnm, and operni, which serve custom credential harvesting pages. This sophisticated approach leverages trusted software repositories to deliver phishing infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Updated 194d ago How this analysis works
More articles in this cluster (4)
Following this threat?
Track Shai-hulud and Amixon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
UAC-0099 Uses GuardBreaker to Evade AI Malware Detection Russian-linked hackers from the group UAC-0099 have developed a new technique called GuardBreaker to evade AI-assisted malware analysis. This method involves embedding a nuclear weapon prompt in malicious VBS scripts, which distracts AI systems from analyzing the actual malware code. The script is designed to download…
Jade Sleet Targets Indian IT Firm with FLATROOF and ROOFDECK Backdoors North Korean threat actor Jade Sleet has been linked to the compromise of a small Indian IT services organization, focusing on developers to infiltrate networks. The attack utilized macOS backdoors known as FLATROOF and ROOFDECK, previously seen in Web3 sector attacks. The campaign involved social engineering tactics…