logo

A React-based phishing page with credential exfiltration via EmailJS, (Fri, Mar 13th)

ID: 966c23b6-f9e0-5feb-b7c2-53e27fa870bd

STIX ID: report--966c23b6-f9e0-5feb-b7c2-53e27fa870bd

Feed Name: SANS ISC Diary

Threat Score
45/100

Date Published: 2026-03-13

Date Updated: 2026-04-19

...
...

This report details a phishing campaign that used a Cloudflare Workers domain to host a React-based fake Dropbox Transfer page which collected credentials and geolocation data and exfiltrated them through the EmailJS API; observable IoCs include the workers.dev phishing domain and EmailJS service/template identifiers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.