LWA-2026-4453 confirmed malware

operni@1.2.7

Malicious code in operni (npm)

T1566 · PhishingT1552.001 · Credentials In FilesT1059.007 · JavaScript

Analysis

The sole file reps/template.min.js builds a two-stage phishing page: Stage 1 is a "Micro-Share secure file sharing" page claiming documents from "[account]"; Stage 2 is a Microsoft-branded sign-in form that prompts for email/credentials. On form submit, it redirects the victim to login[.]siemens-energy[.]icu (a typosquatted Siemens Energy domain). The code includes bot-detection (navigator.webdriver, user-agent checks, honeypot fields) and anti-copy protections. No lifecycle hooks, no Node.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 09:29 PM
analyzed
Jun 11, 2026, 09:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.