Typosquatted npm packages used to steal cloud and CI/CD secrets
2026-05-29T14:52:21Z•f1af9295d64a4fafa00a2330ef638bf9b6a5ed788495d508cd097935fdc61f6e
AI-assisted-phishingCI/CDConfluenceF5-BIG-IPGPU-miningKerberos-relayMini Shai-HuludSEO-poisoningScreenConnectStorm-2697The Gentlemencloud-credentialscredential-theftcryptojackingdetection-mitigationlateral-movementlinux-intrusionmalicious-packagesnpmransomwareself-propagationsupply-chainthreat-inteltyposquatting
What happened
This Microsoft Security Blog feed highlights multiple active threat campaigns and defensive guidance from May 2026. Key items: (1) Typosquatted and/or compromised npm packages (including compromised @antv packages / Mini Shai‑Hulud) are being used to exfiltrate cloud and CI/CD secrets from developer and Linux automation environments during npm install — targeting GitHub, AWS, Kubernetes, Vault, npm, 1Password and other credentials. (2) The Gentlemen ransomware (Go-based, used by Storm‑2697 affiliates) uses per-file ephemeral key encryption plus an aggressive self‑propagation/lateral movement模块
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- f1af9295d64a4fafa00a2330ef638bf9b6a5ed788495d508cd097935fdc61f6e
- Enrichment time
- 2026-05-29T14:52:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.