AI brands as bait: How threat actors are using the AI hype in social engineering

2026-06-09T14:52:19Z5414efdd3abcb27284fda1e63bf42a166766fe550963379188a19e5510b5a490
AI social engineeringCI/CD secretsCI/CD securityClaude CodeGPU miningGartnerGitHub ActionsMDASHMiasmaScreenConnectThe Gentlemenagentic AIcredential theftcryptojackingdependency confusionendpoint protectionfailure modesnpm supply chainprompt injectionransomwareself-propagating malwaresupply chain compromisetyposquatting

What happened

Collection of Microsoft Security Blog posts (May–June 2026) describing multiple high-risk supply chain and AI-related threats and defensive guidance. Key items: a prompt-injection flaw in the Claude Code GitHub Action that could expose workflow secrets (responsible disclosure and mitigation by Anthropic); a large npm supply-chain compromise (Miasma) impacting 90+ @redhat-cloud-services package versions that stole GitHub, cloud, and local credentials and self-republished like a worm; several dependency‑confusion and typosquatting npm campaigns designed to profile developer/build environments or

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
5414efdd3abcb27284fda1e63bf42a166766fe550963379188a19e5510b5a490
Enrichment time
2026-06-09T14:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AI brands as bait: How threat actors are using the AI hype in social engineering · Baitaphish