The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1)

2026-05-04T20:51:51Z40a98c0a84f6190630cd2decdff8cf4f2e910651e29a04969a72472c60b02690
agentcoreai-securityairsnitch','tgr-sta-1030','iran-cyber-activity','detection-tele-amazon-bedrockawsaxios-supply-chainci-cd-persistencecloud-securitycredential-exposurecve-2023-33538data-exfiltrationdns-tunnelinggenai-browser-extensionsidentity-abusekubernetesmiraimulti-stage-attacknpmprompt-injectionsandbox-escapesupply-chaintp-linkunit42wifiwormable-malware

What happened

A Unit 42 RSS roundup covering multiple high-impact threats and research: evolving npm supply-chain attacks (including wormable malware, CI/CD persistence and multi-stage infections); active exploitation attempts against TP-Link command-injection CVE-2023-33538 with Mirai-like payloads; a widespread Axios supply-chain compromise; escalating cloud and Kubernetes threats including identity abuse; critical Amazon Bedrock/AgentCore issues (broad IAM “God Mode”, sandbox escape via DNS tunneling and credential exposure); high-risk GenAI browser extensions that intercept prompts and exfiltrate data;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
40a98c0a84f6190630cd2decdff8cf4f2e910651e29a04969a72472c60b02690
Enrichment time
2026-05-04T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) · Baitaphish