Malicious npm packages abuse dependency confusion to profile developer environments
2026-06-01T08:52:24Z•4aeb0aae122a78dde6f50fc1f94701e5dc0156f7d1c3fd12c55d27f5ddb2fc96
CI/CDMini Shai-Huludcredential-theftdependency-confusiondetectiondeveloper-environment-profilingmalwaremitigationnpmsecrets-exfiltrationsoftware-supply-chaintyposquatting
What happened
Microsoft Threat Intelligence documented a series of supply‑chain attacks in May 2026 that abused npm package discovery (including dependency confusion and typosquatting) to profile developer and build environments and steal CI/CD and cloud credentials. One campaign deployed 33 malicious npm packages that executed during npm install to collect reconnaissance from developer and automation systems; related reports describe compromised @antv packages and the “Mini Shai‑Hulud” payload that exfiltrates secrets from GitHub, AWS, Kubernetes, Vault, npm, and 1Password. Microsoft’s posts include attack
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 4aeb0aae122a78dde6f50fc1f94701e5dc0156f7d1c3fd12c55d27f5ddb2fc96
- Enrichment time
- 2026-06-01T08:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.