Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks
2023-07-06 • Reversing Labs •
ReversingLabs described Operation Brainleeches as a malicious npm campaign in which more than a dozen packages supported both Microsoft 365 phishing and software supply-chain compromise. The first tranche hosted files for phishing emails that launched fake Microsoft login pages and harvested user data, while the second tranche could also implant credential-harvesting scripts into applications that incorporated the packages. The packages mimicked legitimate modules such as jquery, were published by new or thin maintainer accounts between May and June 2023, and contained obfuscated files that signaled malicious intent. The report frames the activity as a dual-use abuse of open-source package infrastructure rather than a DPRK-attributed operation in the provided excerpt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d186505f2fecf7c959f7f0441cf4a22… | 2023-07-06 | 2023-07-06 |
| HASH | 6c315b0907ce516d8b9c12d9609c752… | 2023-07-06 | 2023-07-06 |
| HASH | 47c8cd0a9203cb388e7cf865d3493da… | 2023-07-06 | 2023-07-06 |
| HASH | 10b0c28cac9375cae74464343309a85… | 2023-07-06 | 2023-07-06 |
| HASH | 0b4247bf806e33d8d02b8051224d2d1… | 2023-07-06 | 2023-07-06 |
| HASH | 3eb67cdd1d992db9fa11c924273eef3… | 2023-07-06 | 2023-07-06 |
| HASH | 6c2d2d3c2e68bf3df88a41033a536d1… | 2023-07-06 | 2023-07-06 |
| HASH | 4fd665a5c610a30528417ea0e201e0c… | 2023-07-06 | 2023-07-06 |
| HASH | b29ae6894064b761522e0fffae3c6ae… | 2023-07-06 | 2023-07-06 |
| HASH | 33d1401651e16db2031b597a2a7ac36… | 2023-07-06 | 2023-07-06 |
| HASH | 4b938ea813c9be1feb95fcec52991b5… | 2023-07-06 | 2023-07-06 |
| HASH | 121b10560f54d7767d250e15deb4aff… | 2023-07-06 | 2023-07-06 |
| HASH | 93027a2aa009502ce1992c851d45515… | 2023-07-06 | 2023-07-06 |
| HASH | 5448aa6902a98308836cca6a3ac6e30… | 2023-07-06 | 2023-07-06 |
| URL | http://ourwhite.brainleeches.xyz | 2023-07-06 | 2023-07-06 |
| DOMAIN | ourwhite.brainleeches.xyz | 2023-07-06 | 2023-07-06 |
| DOMAIN | ionic.io | 2023-07-06 | 2023-07-06 |
| IPv4 | 137.184.153.238 | 2023-07-06 | 2023-07-06 |