Malicious npm packages abuse dependency confusion to profile developer environments
2026-06-01T20:52:28Z•53577794051b17e2e4c78aa1e72fbf924bf137874138dae9c18181976b28051b
.NET utilities@antvCI/CDConfluenceF5 BIG-IPGo encryptorKerberos relayMalicious packagesMini Shai-HuludSEO poisoningScreenConnectStorm-2697The Gentlemencloud credentialscredential theftcryptojackingdependency confusionexfiltrationlateral movement','Microsoft Defendernpmnpm installransomwareself-propagationsupply-chaintyposquatting
What happened
Microsoft Security Blog reports multiple active threat campaigns: attackers abused dependency confusion and typosquatting to publish malicious npm packages (including a cluster of 33 packages and compromised @antv packages) that execute during npm install to profile developer/build environments and steal cloud and CI/CD credentials (targeting GitHub, AWS, Kubernetes, Vault, npm, 1Password). Related supply‑chain tradecraft (dependency confusion/typosquatting) and Mini Shai‑Hulud malware enable credential theft in Linux automation/CI environments. Separately, Microsoft details a cryptojacking/SE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 53577794051b17e2e4c78aa1e72fbf924bf137874138dae9c18181976b28051b
- Enrichment time
- 2026-06-01T20:52:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.