Malicious npm packages abuse dependency confusion to profile developer environments

2026-06-01T08:52:24Z4aeb0aae122a78dde6f50fc1f94701e5dc0156f7d1c3fd12c55d27f5ddb2fc96
CI/CDMini Shai-Huludcredential-theftdependency-confusiondetectiondeveloper-environment-profilingmalwaremitigationnpmsecrets-exfiltrationsoftware-supply-chaintyposquatting

What happened

Microsoft Threat Intelligence documented a series of supply‑chain attacks in May 2026 that abused npm package discovery (including dependency confusion and typosquatting) to profile developer and build environments and steal CI/CD and cloud credentials. One campaign deployed 33 malicious npm packages that executed during npm install to collect reconnaissance from developer and automation systems; related reports describe compromised @antv packages and the “Mini Shai‑Hulud” payload that exfiltrates secrets from GitHub, AWS, Kubernetes, Vault, npm, and 1Password. Microsoft’s posts include attack

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
4aeb0aae122a78dde6f50fc1f94701e5dc0156f7d1c3fd12c55d27f5ddb2fc96
Enrichment time
2026-06-01T08:52:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.