Turn specs into evals for any agent with ASSERT
2026-06-11T14:52:17Z•3800012c0b4cb3330deefa7544f3a768b635c2bfe14990c31c217ae96c5151e9
AI-securityASSERTCI/CDagentic-aicredential-stealingdependency-confusionevaluation-frameworkgithub-actionincident-responsenpmprompt-injectionred-teamingsecrets-exfiltrationsocial-engineeringsupply-chaintelemetrytyposquatting
What happened
Collection of Microsoft Security Blog posts (June 2026) describing multiple high-impact threats and defensive guidance for AI and developer supply chains. Key findings: a large-scale npm supply-chain campaign (Miasma) compromised >90 versions of @redhat-cloud-services packages to steal developer, CI/CD, and cloud credentials and propagate by republishing trusted packages; a dependency‑confusion/typosquatting campaign (33 malicious npm packages, Mini Shai‑Hulud and related) profiled environments and stole cloud/CI/CD secrets; a prompt-injection pathway in the Claude Code GitHub Action could exfi
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 3800012c0b4cb3330deefa7544f3a768b635c2bfe14990c31c217ae96c5151e9
- Enrichment time
- 2026-06-11T14:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.