Cyber Security News

New Business Email Protection Technique Blocks the Phishing Email Behind NPM Breach

Supply chain attacks targeting the JavaScript ecosystem have evolved into sophisticated operations combining domain manipulation with social engineering.

On September 8, 2025, threat actors launched a coordinated phishing campaign aimed at compromising high-profile NPM developers.

The attack successfully infiltrated the accounts of developer Josh Junon, known as “qix,” and targeted at least four other maintainers, exposing the vulnerability of software repositories to credential-harvesting tactics.

The compromised packages represented nearly 2.8 billion weekly downloads, positioning this incident among the most significant supply chain threats in NPM’s history.

The phishing emails masqueraded as official NPM security communications, claiming recipients needed to update their two-factor authentication credentials to prevent account suspension.

Fraudulent message masqueraded as a security update (Source – Group-IB)

This urgent messaging created psychological pressure that bypassed traditional user skepticism.

The attacker sent communications from support@npmjs[.]help, a spoofed domain designed to mirror legitimate NPM infrastructure while remaining visually convincing to unsuspecting developers.

Group-IB analysts identified that despite successfully passing standard email authentication protocols including SPF, DKIM, and DMARC, multiple technical indicators revealed the campaign’s malicious intent.

Each email contained a customized phishing link directing victims to a credential harvesting site hosted on npmjs.help. Once developers entered their credentials into the cloned login page, attackers gained full access to their NPM accounts.

The JavaScript Clipper Payload and Cryptocurrency Targeting

With account access secured, threat actors inserted JavaScript clipper malware into twenty popular NPM packages.

This sophisticated payload monitored browser and application activity specifically for cryptocurrency wallet interactions.

When users initiated transactions involving Bitcoin, Ethereum, Solana, Tron, Litecoin, or Bitcoin Cash, the malware intercepted wallet addresses and replaced them with attacker-controlled alternatives, effectively diverting cryptocurrency transfers without user awareness.

Business Email Protection interface showing threat indicators (Source – Group-IB)

This targeted infection mechanism exemplified the precision of modern supply chain compromise operations.

Group-IB’s Business Email Protection platform successfully detected this threat through comprehensive multi-layer analysis.

The detection leveraged domain intelligence via RDAP checks, brand impersonation algorithms, content analysis identifying social engineering patterns, URL inspection revealing credential-capturing functionality, and behavioral analysis exposing fraudulent interface replication.

Following remediation, affected packages were reverted to clean versions and developers regained full account control, preventing widespread downstream compromise.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago