#Brainleeches
Incident/Operation
2023-07-06 • Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks
Operation Brainleeches was a May–June 2023 campaign that placed more than a dozen malicious packages in the npm repository to support both Microsoft 365 phishing and software supply-chain compromise. One package set launched counterfeit sign-in pages from email attachments to harvest user data, while another sought to inject credential-stealing scripts into applications that incorporated the packages. The packages impersonated popular modules, accumulated roughly 1,000 downloads, and were removed shortly after discovery.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days