Cyber Midpoint – 175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

Socket’s Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages that collectively accumulated over 26,000 downloads. The campaign, dubbed “Beamglea” based on consistent artifacts across all packages, represents a novel abuse of npm’s public registry and the unpkg.com CDN to host redirect scripts targeting 135+ industrial, technology, and energy companies […]
Cyber Midpoint – 175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide
Cyber Midpoint – 175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

Socket’s Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages that collectively accumulated over 26,000 downloads. The campaign, dubbed “Beamglea” based on consistent artifacts across all packages, represents a novel abuse of npm’s public registry and the unpkg.com CDN to host redirect scripts targeting 135+ industrial, technology, and energy companies […]

{}
Read more from Tushar Subhra Dutta

Billy Sneed
Author: Billy Sneed

Previous Article

Cyber Midpoint - Forescout exposes TwoNet hacktivists targeting water utility honeypot in latest OT cyberattack findings

Next Article

Cyber Midpoint - FDA announces recall for Johnson & Johnson devices due to cybersecurity risk—customers urged to act

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Pure inspiration, zero spam ✨