Cybersecurity researchers have flagged a new set of 175
malicious packages on the npm registry that have been used to
facilitate credential harvesting attacks as part of an unusual
campaign. The packages have been collectively downloaded 26,000
times, acting as an infrastructure for a widespread phishing
campaign codenamed Beamglea targeting more than 135 industrial,
technology, and energy
Read more https://thehackernews.com/2025/10/175-malicious-npm-packages-with-26000.html

