The npm Threat Landscape: Attack Surface and Mitigations
2026-04-27T20:51:44Z•26b251ff2edd92789a35f56490f05190195e22c4c52cca7edf2c676893d504f2
AI-securityAxiosCI/CD persistenceCVE-2023-33538MiraiTeamPCPVect-ransomwareagentcoreair-snitchamazon-bedrockautonomous-agentsdns-tunnelingfrontier-aiiam-privilege-escalationkubernetes-threatsmulti-agent-attacksmulti-stage-attacknpmprompt-injectionsandbox-escapesupply-chainvertex-aiwifi-bypasswormable-malware
What happened
Unit 42 research (Apr 2026) highlights an intensifying threat landscape across software supply chains, cloud AI agents, and networking: npm supply‑chain attacks (wormable malware, CI/CD persistence, multi‑stage droppers), widespread supply‑chain incidents (Axios, TeamPCP with ties to Vect ransomware), and active exploitation attempts of TP‑Link command‑injection CVE‑2023‑33538 with Mirai‑style payloads. Parallel trends show AI/agent risks — frontier models enabling autonomous zero‑day discovery and offensive multi‑agent cloud attacks, prompt‑injection and over‑privileged agents (Amazon Bedrock
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 26b251ff2edd92789a35f56490f05190195e22c4c52cca7edf2c676893d504f2
- Enrichment time
- 2026-04-27T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.