The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1)
2026-05-04T20:51:51Z•40a98c0a84f6190630cd2decdff8cf4f2e910651e29a04969a72472c60b02690
agentcoreai-securityairsnitch','tgr-sta-1030','iran-cyber-activity','detection-tele-amazon-bedrockawsaxios-supply-chainci-cd-persistencecloud-securitycredential-exposurecve-2023-33538data-exfiltrationdns-tunnelinggenai-browser-extensionsidentity-abusekubernetesmiraimulti-stage-attacknpmprompt-injectionsandbox-escapesupply-chaintp-linkunit42wifiwormable-malware
What happened
A Unit 42 RSS roundup covering multiple high-impact threats and research: evolving npm supply-chain attacks (including wormable malware, CI/CD persistence and multi-stage infections); active exploitation attempts against TP-Link command-injection CVE-2023-33538 with Mirai-like payloads; a widespread Axios supply-chain compromise; escalating cloud and Kubernetes threats including identity abuse; critical Amazon Bedrock/AgentCore issues (broad IAM “God Mode”, sandbox escape via DNS tunneling and credential exposure); high-risk GenAI browser extensions that intercept prompts and exfiltrate data;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 40a98c0a84f6190630cd2decdff8cf4f2e910651e29a04969a72472c60b02690
- Enrichment time
- 2026-05-04T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.