Replies: 9 comments 7 replies
-
I received this email too. What can we do to help get the site taken down? I reported the site at:
Anything else? |
Beta Was this translation helpful? Give feedback.
-
Received this email as well! |
Beta Was this translation helpful? Give feedback.
-
Submitted it to https://safebrowsing.google.com/safebrowsing/report_phish/ No idea if multiple people reporting it helps this process, but at least once its flagged it'll show a warning page, in Chrome at least. edit: sorry, my eyes somehow missed the fact that this was already suggested |
Beta Was this translation helpful? Give feedback.
-
This has already caused severe harm: |
Beta Was this translation helpful? Give feedback.
-
As of 22025-09-08T20:22:07Z the domain "npmjs.help" appears to have been taken down. |
Beta Was this translation helpful? Give feedback.
-
To Identify any suspicious email or website, go to virustotal.com and paste the domain and email you received. |
Beta Was this translation helpful? Give feedback.
-
Has there been any communication from npm on this issue? We know qix's credentials were stolen and used to publish malware, and other maintainers (duckdb). So while phishing / credential loss is always a risk it seems this instance was outstandingly successful. Is npm collecting a list of all packages / maintainers compromized? |
Beta Was this translation helpful? Give feedback.
-
Ideas to Improve NPM Account Security #173027 |
Beta Was this translation helpful? Give feedback.
-
@Marsup I'm seriously curious why npm logo is shown next to "to marsup" because it looks like a valid brand-controlled logo via BIMI but if so it impairs DMARC protection's reliability; faking brand indicator is considered difficult as it requires strict steps like trademarking logo, if I understand correctly. There's a possibility that the logo was somehow generated by your mail client... which client do you use? Or you mocked image? |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
General
Body
Hi,
I just received what I strongly believe to be a phishing email from [email protected].
The links are also leading to npmjs.help, the domain was registered 3 days ago.
Stay safe out there.
Beta Was this translation helpful? Give feedback.
All reactions