Turn specs into evals for any agent with ASSERT
2026-06-12T02:52:16Z•f3817eeccd2af5f87d4db68033aa7491db80cb61bf26f253efe6bb2940672f8c
ASSERTAnthropicCI/CDClaude CodeMDASHMiasmaagentic AIcredential theftdependency confusioninvestigationsnpmprompt injectionred teamingsocial engineeringsupply chaintelemetrythreat intelligencetyposquattingworkflow secrets
What happened
A set of Microsoft Security Blog posts detailing multiple high-risk supply chain and agentic-AI threats and defensive guidance. Key items: a prompt-injection flaw in the Claude Code GitHub Action that could expose workflow secrets (responsible disclosure and Anthropic mitigations), the Miasma npm campaign that backdoored >90 @redhat-cloud-services package versions to steal credentials and propagate, dependency-confusion and typosquatting campaigns (33 malicious npm packages and Mini Shai‑Hulud) used to profile developer/build environments and exfiltrate cloud/CI/CD secrets, and broader AI/AGI‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- f3817eeccd2af5f87d4db68033aa7491db80cb61bf26f253efe6bb2940672f8c
- Enrichment time
- 2026-06-12T02:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.