LWA-2026-4453 confirmed malware
operni@1.2.7
Malicious code in operni (npm)
T1566 · PhishingT1552.001 · Credentials In FilesT1059.007 · JavaScript
Analysis
The sole file reps/template.min.js builds a two-stage phishing page: Stage 1 is a "Micro-Share secure file sharing" page claiming documents from "[account]"; Stage 2 is a Microsoft-branded sign-in form that prompts for email/credentials. On form submit, it redirects the victim to login[.]siemens-energy[.]icu (a typosquatted Siemens Energy domain). The code includes bot-detection (navigator.webdriver, user-agent checks, honeypot fields) and anti-copy protections. No lifecycle hooks, no Node.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:29 PM
- analyzed
- Jun 11, 2026, 09:35 PM
Related advisories
- oprnm@1.0.0
- nhdxzthponv5@1.0.0
- internallib_v557@1.0.5
- worker-build@9.0.1
- index-ulid@3.0.2
- npm-scanner@1.0.0
- npmjs-doc-builder@1.0.1
- npm-bs58.js@2.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.