New Phishing Campaign Abuses npm Packages to Steal Corporate Credentials

Security researchers have uncovered a long-running and highly targeted phishing operation that abuses the npm ecosystem to steal login credentials from professionals working in sensitive industries. The campaign, which has been active for several months, relies on malicious npm packages…





