AI brands as bait: How threat actors are using the AI hype in social engineering
2026-06-09T14:52:19Z•5414efdd3abcb27284fda1e63bf42a166766fe550963379188a19e5510b5a490
AI social engineeringCI/CD secretsCI/CD securityClaude CodeGPU miningGartnerGitHub ActionsMDASHMiasmaScreenConnectThe Gentlemenagentic AIcredential theftcryptojackingdependency confusionendpoint protectionfailure modesnpm supply chainprompt injectionransomwareself-propagating malwaresupply chain compromisetyposquatting
What happened
Collection of Microsoft Security Blog posts (May–June 2026) describing multiple high-risk supply chain and AI-related threats and defensive guidance. Key items: a prompt-injection flaw in the Claude Code GitHub Action that could expose workflow secrets (responsible disclosure and mitigation by Anthropic); a large npm supply-chain compromise (Miasma) impacting 90+ @redhat-cloud-services package versions that stole GitHub, cloud, and local credentials and self-republished like a worm; several dependency‑confusion and typosquatting npm campaigns designed to profile developer/build environments or
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 5414efdd3abcb27284fda1e63bf42a166766fe550963379188a19e5510b5a490
- Enrichment time
- 2026-06-09T14:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.