LWA-2026-4455 confirmed malware

oprnm@1.0.0

Malicious code in oprnm (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1566 · PhishingT1552.001 · Credentials In Files

Analysis

oprnm@1.0.0 is a Microsoft credential-phishing kit distributed via npm. It serves a two-stage client-side page: Stage 1 is a fake "Micro-Share" document-sharing UI prompting a Download click; Stage 2 renders a counterfeit Microsoft sign-in page that collects the victim's credentials and redirects the browser to login[.]siemens-energy[.]icu. The page disables right-click/copy/paste, checks for headless browsers (navigator.webdriver, plugin count, screen dimensions), and includes honeypot fields. It has no lifecycle hooks and does not run on install; it is a static phishing template meant to be served as a web page to steal end-user Microsoft credentials.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 09:29 PM
analyzed
Jun 11, 2026, 09:34 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.