CMC America is a cyber threat actor associated with distributing malicious npm packages that serve custom credential harvesting pages.
CMC America is a organization tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 23, 2026; most recent activity January 23, 2026.
CMC America is a cyber threat actor associated with distributing malicious npm packages that serve custom credential harvesting pages. The group leverages the npm ecosystem to host phishing assets that capture user credentials, highlighting supply-chain-like risks in popular development tooling and highlighting a growing vector for credential-theft campaigns.
A new phishing campaign has emerged, utilizing malicious npm packages to target employees in industrial, energy, and healthcare sectors across Europe, the Middle East, and the United States. Attackers have published…
CMC America is a cyber threat actor associated with distributing malicious npm packages that serve custom credential harvesting pages.
The most recent intelligence report mentioning CMC America on ThreatCluster is dated January 23, 2026.
Across ThreatCluster reporting, CMC America most frequently co-occurs with Phishing, Amixon, CQFD Composites, Emagine, Ingeteam, among 12 tracked related entities.
The most significant recent cluster is “Phishing Campaign Utilizes Malicious npm Packages Targeting Various Sectors” (4 articles · Updated January 23, 2026). CMC America appears across 1 threat cluster in total, listed above with sources.
CMC America appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.