Malicious npm packages abuse dependency confusion to profile developer environments

2026-06-02T14:52:16Z4430f3248ad320137d0b34002dd6a497d912873b0b6b7df229270a254d89d5cb
.NET utilitiesCI/CDConfluenceF5 BIG-IPGPU miningKerberos relay','lateral movementMini Shai‑HuludSEO poisoningScreenConnectStorm-2697The Gentlemenbuild environmentscompromised packagescredential theftcryptojackingdependency confusiondetectionmalicious npm packagesmitigationnpmransomwarereconnaissancesecretssupply chaintyposquatting

What happened

Microsoft Security Blog posts (late May 2026) detail multiple active campaigns and threat research: a dependency‑confusion campaign that published 33 malicious npm packages to profile developer and build environments; several typosquatted and compromised npm package campaigns (including Mini Shai‑Hulud and compromised @antv packages) that execute during npm install to harvest cloud and CI/CD secrets (targeting GitHub, AWS, Kubernetes, Vault, npm, 1Password); and guidance on detection and mitigation for supply‑chain and developer‑environment exposures. Additional reporting covers The Gentlemen—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
4430f3248ad320137d0b34002dd6a497d912873b0b6b7df229270a254d89d5cb
Enrichment time
2026-06-02T14:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Malicious npm packages abuse dependency confusion to profile developer environments · Baitaphish