LWA-2026-4454 confirmed malware
opresc@1.0.0
Malicious code in opresc (npm)
T1056.001 · KeyloggingT1195.002 · Compromise Software Supply Chain
Analysis
opresc@1.0.0 is a credential-phishing kit. template.min.js renders a fake Microsoft sign-in page inside a "Micro-Share" document-sharing flow; on form submission it redirects to login[.]siemens-energy[.]icu/DIVzTaSF, a credential-capture endpoint targeting Microsoft account credentials. The page includes anti-bot measures (navigator.webdriver and headless-browser checks) and honeypot fields to evade automated crawlers. It has no lifecycle hooks; the sole shipped artifact is the phishing page.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:29 PM
- analyzed
- Jun 11, 2026, 09:34 PM
Related advisories
- hex-type@3.0.2
- log-input@1.0.5
- os-ulid-void@3.0.2
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- stellarfixer@1.0.0
- approval-guardian@1.0.8
- system-performance-helper@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.