Malicious npm packages abuse dependency confusion to profile developer environments

2026-05-30T14:52:17Zc1fbf2c81680b5616cc3cb140bb6422ac4ab758788706ea0417d8007502adf0f
@antvCI/CDConfluenceF5 BIG-IPGPU miningMicrosoft Threat IntelligenceMini Shai-HuludSEO poisoningScreenConnectThe Gentlemencloud credentialscredential theftcryptojackingdependency confusiondetection and mitigationidentity compromiselateral movementmalicious npm packagesnpmransomwareself-propagating malwaresoftware supply chainsupply chaintyposquatting

What happened

Multiple Microsoft Security Blog reports describe active malicious campaigns targeting developer and enterprise environments. Key activity includes: a dependency‑confusion campaign that published 33 malicious npm packages to profile developer/build environments; typosquatted and compromised npm packages (including the Mini Shai‑Hulud/compromised @antv cluster) that exfiltrate cloud and CI/CD credentials during npm install; a self‑propagating Go ransomware family (“The Gentlemen”) used for aggressive lateral movement; a cryptojacking campaign abusing poisoned search results, ScreenConnect, and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
c1fbf2c81680b5616cc3cb140bb6422ac4ab758788706ea0417d8007502adf0f
Enrichment time
2026-05-30T14:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.