New npm supply-chain attack self-spreads to steal auth tokens

2026-04-22T13:23:33Z562739d01411c640b15e92b232a39aa3e09af5fa1c4a51a0afd7e85a4e7621d4
ASP.NETAndroid-malware-NFC','KelpDAO','Lazarus','BlackCat','crypto-heilApache-ActiveMQCISACatalystFrance-TitresGoGraLotusMicrosoftMicrosoft-Graph-APINGateSD-WANSharePointVenezuelaauth-tokenscode-injectiondata-breachmalicious-packagesmalwarenpmout-of-band-patchprivilege-escalationsupply-chainwiperzero-day

What happened

Multiple active security incidents and vulnerabilities: a new npm supply‑chain campaign is stealing developer auth tokens and self‑spreading via compromised publisher accounts; Microsoft-related items include a Teams Efficiency Mode rollout, a Graph API code change breaking Universal Print and being abused for stealthy GoGra Linux malware comms, and out‑of‑band critical ASP.NET Core privilege‑escalation patches while >1,300 SharePoint servers remain exposed to an actively exploited spoofing zero‑day. CISA flagged an actively exploited Catalyst SD‑WAN flaw; Shadowserver found ~6,400 Apache Acti

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
562739d01411c640b15e92b232a39aa3e09af5fa1c4a51a0afd7e85a4e7621d4
Enrichment time
2026-04-22T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.