CMC America — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 23, 2026
Last Seen
January 23, 2026

CMC America is a cyber threat actor associated with distributing malicious npm packages that serve custom credential harvesting pages.

CMC America is a organization tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 23, 2026; most recent activity January 23, 2026.

Overview

CMC America is a cyber threat actor associated with distributing malicious npm packages that serve custom credential harvesting pages. The group leverages the npm ecosystem to host phishing assets that capture user credentials, highlighting supply-chain-like risks in popular development tooling and highlighting a growing vector for credential-theft campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • Gone Phishin': npm Packages Serving Custom Credential Harvesting Pages — Aikido.Dev · January 23, 2026

Frequently asked questions

What is CMC America?

CMC America is a cyber threat actor associated with distributing malicious npm packages that serve custom credential harvesting pages.

Is CMC America still active?

The most recent intelligence report mentioning CMC America on ThreatCluster is dated January 23, 2026.

What is CMC America associated with?

Across ThreatCluster reporting, CMC America most frequently co-occurs with Phishing, Amixon, CQFD Composites, Emagine, Ingeteam, among 12 tracked related entities.

What are the latest developments involving CMC America?

The most significant recent cluster is “Phishing Campaign Utilizes Malicious npm Packages Targeting Various Sectors” (4 articles · Updated January 23, 2026). CMC America appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on CMC America?

CMC America appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown