logo

Phishing as a Service to Ramp Up Supply Chain Attacks

ID: 8d66a251-9653-57fa-85c4-9bd7096fce81

STIX ID: report--8d66a251-9653-57fa-85c4-9bd7096fce81

Feed Name: Aqua Security Blog

Threat Score
78/100

Date Published: 2022-09-13

Date Updated: 2026-04-26

...
...

Researchers observed EvilProxy (Moloch), a Phishing-as-a-Service that operates as a reverse proxy to transparently intercept login flows, capture credentials and MFA tokens, and hijack session cookies to perform account takeovers. The report warns that attackers are targeting both mainstream services (Google, Microsoft, Facebook, Twitter, etc.) and developer/package registries (GitHub, PyPI, RubyGems, npm), increasing risk of software supply-chain compromises, and cites recent incidents (e.g., a malicious PyPI update, exposed Travis CI logs, and stolen OAuth tokens) to illustrate potential impact and mitigation recommendations including CNAPP and runtime protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.