New npm supply-chain attack self-spreads to steal auth tokens
2026-04-22T13:23:33Z•562739d01411c640b15e92b232a39aa3e09af5fa1c4a51a0afd7e85a4e7621d4
ASP.NETAndroid-malware-NFC','KelpDAO','Lazarus','BlackCat','crypto-heilApache-ActiveMQCISACatalystFrance-TitresGoGraLotusMicrosoftMicrosoft-Graph-APINGateSD-WANSharePointVenezuelaauth-tokenscode-injectiondata-breachmalicious-packagesmalwarenpmout-of-band-patchprivilege-escalationsupply-chainwiperzero-day
What happened
Multiple active security incidents and vulnerabilities: a new npm supply‑chain campaign is stealing developer auth tokens and self‑spreading via compromised publisher accounts; Microsoft-related items include a Teams Efficiency Mode rollout, a Graph API code change breaking Universal Print and being abused for stealthy GoGra Linux malware comms, and out‑of‑band critical ASP.NET Core privilege‑escalation patches while >1,300 SharePoint servers remain exposed to an actively exploited spoofing zero‑day. CISA flagged an actively exploited Catalyst SD‑WAN flaw; Shadowserver found ~6,400 Apache Acti
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 562739d01411c640b15e92b232a39aa3e09af5fa1c4a51a0afd7e85a4e7621d4
- Enrichment time
- 2026-04-22T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.