Malicious npm packages abuse dependency confusion to profile developer environments
2026-06-02T02:52:16Z•6802f6c2dc749109b4f3a7ebe29280a552eca8f4c4c64f27ac684c398b71e6cb
What happened
Microsoft Security Blog posts (May 2026) describe multiple active supply‑chain and post‑compromise campaigns: a dependency‑confusion campaign that published 33 malicious npm packages to profile developer and build environments; typosquatted and compromised npm packages (including Mini Shai‑Hulud and compromised @antv packages) that execute during npm install to steal cloud and CI/CD credentials (GitHub, AWS, Kubernetes, Vault, npm, 1Password); and related threats including a cryptojacking campaign abusing ScreenConnect and .NET utilities, a self‑propagating Go ransomware family (“The Gentlemen
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 6802f6c2dc749109b4f3a7ebe29280a552eca8f4c4c64f27ac684c398b71e6cb
- Enrichment time
- 2026-06-02T02:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.