Malicious npm packages abuse dependency confusion to profile developer environments
2026-05-30T08:52:22Z•1a6b4017d9e92ebe38a9db18cd95f7bf1cd0c89c74e8de9d192541c3ec0b71f4
CI/CDMini Shai‑Huludantvcloud credentialscompromised-packagescredential theftdependency confusiondeveloper environment reconnaissancemalicious packagesnpmsupply chaintyposquatting
What happened
Microsoft Security Blog (May 2026) details multiple malicious npm package campaigns that abuse dependency confusion, typosquatting, and compromised packages to profile developer and build environments and to steal cloud and CI/CD credentials. The activity includes 33 malicious npm packages used for reconnaissance and exfiltration, the Mini Shai‑Hulud payload (compromised @antv packages) that runs during npm install and harvests credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password, and related supply‑chain tradecraft. The reports describe the attack chains, observed techniques,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 1a6b4017d9e92ebe38a9db18cd95f7bf1cd0c89c74e8de9d192541c3ec0b71f4
- Enrichment time
- 2026-05-30T08:52:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.