Turn specs into evals for any agent with ASSERT

2026-06-11T14:52:17Z3800012c0b4cb3330deefa7544f3a768b635c2bfe14990c31c217ae96c5151e9
AI-securityASSERTCI/CDagentic-aicredential-stealingdependency-confusionevaluation-frameworkgithub-actionincident-responsenpmprompt-injectionred-teamingsecrets-exfiltrationsocial-engineeringsupply-chaintelemetrytyposquatting

What happened

Collection of Microsoft Security Blog posts (June 2026) describing multiple high-impact threats and defensive guidance for AI and developer supply chains. Key findings: a large-scale npm supply-chain campaign (Miasma) compromised >90 versions of @redhat-cloud-services packages to steal developer, CI/CD, and cloud credentials and propagate by republishing trusted packages; a dependency‑confusion/typosquatting campaign (33 malicious npm packages, Mini Shai‑Hulud and related) profiled environments and stole cloud/CI/CD secrets; a prompt-injection pathway in the Claude Code GitHub Action could exfi

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
3800012c0b4cb3330deefa7544f3a768b635c2bfe14990c31c217ae96c5151e9
Enrichment time
2026-06-11T14:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Turn specs into evals for any agent with ASSERT · Baitaphish