oprnm@1.0.0
Malicious code in oprnm (npm)
Analysis
oprnm@1.0.0 is a Microsoft credential-phishing kit distributed via npm. It serves a two-stage client-side page: Stage 1 is a fake "Micro-Share" document-sharing UI prompting a Download click; Stage 2 renders a counterfeit Microsoft sign-in page that collects the victim's credentials and redirects the browser to login[.]siemens-energy[.]icu. The page disables right-click/copy/paste, checks for headless browsers (navigator.webdriver, plugin count, screen dimensions), and includes honeypot fields. It has no lifecycle hooks and does not run on install; it is a static phishing template meant to be served as a web page to steal end-user Microsoft credentials.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:29 PM
- analyzed
- Jun 11, 2026, 09:34 PM
Related advisories
- nhdxzthponv5@1.0.0
- operni@1.2.7
- internallib_v557@1.0.5
- worker-build@9.0.1
- index-ulid@3.0.2
- npm-scanner@1.0.0
- npmjs-doc-builder@1.0.1
- npm-bs58.js@2.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.