Skip to content
Phishing Campaign Utilizes Malicious npm Packages Targeting Various Sectors

Phishing Campaign Utilizes Malicious npm Packages Targeting Various Sectors

First seen 23 Jan 2026, 22:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A new phishing campaign has emerged, utilizing malicious npm packages to target employees in industrial, energy, and healthcare sectors across Europe, the Middle East, and the United States. Attackers have published multiple versions of these packages, including flockiali, opresc, prndn, oprnm, and operni, which serve custom credential harvesting pages. This sophisticated approach leverages trusted software repositories to deliver phishing infrastructure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track Shai-hulud and Amixon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed