Malicious npm packages abuse dependency confusion to profile developer environments

2026-05-30T08:52:22Z1a6b4017d9e92ebe38a9db18cd95f7bf1cd0c89c74e8de9d192541c3ec0b71f4
CI/CDMini Shai‑Huludantvcloud credentialscompromised-packagescredential theftdependency confusiondeveloper environment reconnaissancemalicious packagesnpmsupply chaintyposquatting

What happened

Microsoft Security Blog (May 2026) details multiple malicious npm package campaigns that abuse dependency confusion, typosquatting, and compromised packages to profile developer and build environments and to steal cloud and CI/CD credentials. The activity includes 33 malicious npm packages used for reconnaissance and exfiltration, the Mini Shai‑Hulud payload (compromised @antv packages) that runs during npm install and harvests credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password, and related supply‑chain tradecraft. The reports describe the attack chains, observed techniques,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
1a6b4017d9e92ebe38a9db18cd95f7bf1cd0c89c74e8de9d192541c3ec0b71f4
Enrichment time
2026-05-30T08:52:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.