Typosquatted npm packages used to steal cloud and CI/CD secrets

2026-05-29T14:52:21Zf1af9295d64a4fafa00a2330ef638bf9b6a5ed788495d508cd097935fdc61f6e
AI-assisted-phishingCI/CDConfluenceF5-BIG-IPGPU-miningKerberos-relayMini Shai-HuludSEO-poisoningScreenConnectStorm-2697The Gentlemencloud-credentialscredential-theftcryptojackingdetection-mitigationlateral-movementlinux-intrusionmalicious-packagesnpmransomwareself-propagationsupply-chainthreat-inteltyposquatting

What happened

This Microsoft Security Blog feed highlights multiple active threat campaigns and defensive guidance from May 2026. Key items: (1) Typosquatted and/or compromised npm packages (including compromised @antv packages / Mini Shai‑Hulud) are being used to exfiltrate cloud and CI/CD secrets from developer and Linux automation environments during npm install — targeting GitHub, AWS, Kubernetes, Vault, npm, 1Password and other credentials. (2) The Gentlemen ransomware (Go-based, used by Storm‑2697 affiliates) uses per-file ephemeral key encryption plus an aggressive self‑propagation/lateral movement模块

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
f1af9295d64a4fafa00a2330ef638bf9b6a5ed788495d508cd097935fdc61f6e
Enrichment time
2026-05-29T14:52:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.