Malicious npm packages abuse dependency confusion to profile developer environments

2026-05-31T20:52:16Zafd3925bbe79bdcf938a61f1f7711215331fc113f63afe12cb7302f7ca130338
@antvCI/CDConfluenceF5 BIG-IPGPU miningGoKerberos relayLinux intrusionMicrosoft DefenderMini Shai-HuludSEO poisoningScreenConnectThe Gentlemencloud credentialscredential theftcryptojackingdependency confusiondetectionlateral movementmitigationnpmransomwareself-propagating malwaresupply chaintyposquatting

What happened

Microsoft Security Blog reports multiple active threats and investigations: a dependency‑confusion campaign using 33 malicious npm packages to profile developer and build environments; typosquatted and compromised npm packages (including the Mini Shai‑Hulud and compromised @antv packages) used to steal cloud and CI/CD credentials during npm install; a self‑propagating Go ransomware family (“The Gentlemen”) that performs aggressive lateral movement; a cryptojacking campaign abusing SEO poisoning, ScreenConnect, and .NET utilities to deploy GPU miners; and a multi‑stage Linux intrusion that pivt

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
afd3925bbe79bdcf938a61f1f7711215331fc113f63afe12cb7302f7ca130338
Enrichment time
2026-05-31T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Malicious npm packages abuse dependency confusion to profile developer environments · Baitaphish