The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21)
2026-05-21T20:51:37Z•1d65d5c87283e5947b243a903bfadeb92f55c0dc153d9b9c1b94203145d297f3
AD CSAI/browser extensionsActive Directory Certificate ServicesAirSnitchCI/CD persistenceCopy FailGremlin stealerLinux kernel LPEMiraiPAN‑OSShai HuludTGR‑STA‑1030TP‑LinkTamperedChefWi‑Fi attacksautonomous cloud attackscaptive portaldetection and responsefrontier AImalvertisingnpmobfuscationsession hijackingsupply‑chainwormable malware
What happened
Palo Alto Unit 42 published a batch of May 2026 research covering multiple high-risk threats and defensive guidance. Highlights include: an updated analysis of the npm supply‑chain attack surface (post‑Shai Hulud) describing wormable malware, CI/CD persistence and multi‑stage attacks; tracking of TamperedChef clusters using trojanized apps, malvertising, and certificate/code reuse; evolution of the Gremlin stealer with advanced obfuscation and session‑stealing techniques; detailed AD CS (Active Directory Certificate Services) misuse and escalation methods with behavioral detection guidance; a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 1d65d5c87283e5947b243a903bfadeb92f55c0dc153d9b9c1b94203145d297f3
- Enrichment time
- 2026-05-21T20:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.