Malicious npm packages abuse dependency confusion to profile developer environments

2026-06-01T20:52:28Z53577794051b17e2e4c78aa1e72fbf924bf137874138dae9c18181976b28051b
.NET utilities@antvCI/CDConfluenceF5 BIG-IPGo encryptorKerberos relayMalicious packagesMini Shai-HuludSEO poisoningScreenConnectStorm-2697The Gentlemencloud credentialscredential theftcryptojackingdependency confusionexfiltrationlateral movement','Microsoft Defendernpmnpm installransomwareself-propagationsupply-chaintyposquatting

What happened

Microsoft Security Blog reports multiple active threat campaigns: attackers abused dependency confusion and typosquatting to publish malicious npm packages (including a cluster of 33 packages and compromised @antv packages) that execute during npm install to profile developer/build environments and steal cloud and CI/CD credentials (targeting GitHub, AWS, Kubernetes, Vault, npm, 1Password). Related supply‑chain tradecraft (dependency confusion/typosquatting) and Mini Shai‑Hulud malware enable credential theft in Linux automation/CI environments. Separately, Microsoft details a cryptojacking/SE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
53577794051b17e2e4c78aa1e72fbf924bf137874138dae9c18181976b28051b
Enrichment time
2026-06-01T20:52:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.