oprnm@1.0.0
Malicious code in oprnm (npm)
Analysis
oprnm@1.0.0 is a Microsoft credential-phishing kit distributed via npm. It serves a two-stage client-side page: Stage 1 is a fake "Micro-Share" document-sharing UI prompting a Download click; Stage 2 renders a counterfeit Microsoft sign-in page that collects the victim's credentials and redirects the browser to login[.]siemens-energy[.]icu. The page disables right-click/copy/paste, checks for headless browsers (navigator.webdriver, plugin count, screen dimensions), and includes honeypot fields. It has no lifecycle hooks and does not run on install; it is a static phishing template meant to be served as a web page to steal end-user Microsoft credentials.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:29 PM
- analyzed
- Jun 11, 2026, 09:34 PM
Related advisories
- lufxchwmxwyps@1.0.0
- @worrisome/aaaa@1.0.0
- tib2jcvowuyma@1.0.0
- tibcwmpoeafh@1.0.0
- caphsmgiwy@1.0.0
- tuxcmdfhjkw@1.0.0
- dzcvhfruwluwe@1.0.0
- nhdxzthponv5@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.