The npm Threat Landscape: Attack Surface and Mitigations

2026-04-25T08:51:47Z635593a09240e1b7fef64bd0cd4fe3ce3b933d2a5295cbe3305fda01f59269c4
AWS-BedrockAgentCoreAirSnitchAxios-supply-chainCI/CD-persistenceCVE-2023-33538DNS-tunnelingIAM-privilege-escalationKubernetesMiraiTGR-STA-1030','Iran-cyberactivity','frontier-AI','autonomous-attTP-LinkTeamPCPVect-ransomwareVertex-AIWiFi-bypasscloud-securitycredential-exposuremalwaremulti-agentnpmprompt-injectionsandbox-escapesupply-chainwormable-malware

What happened

Unit 42 published multiple research posts covering elevated threats across supply chains, cloud/A I platforms, IoT, and wireless. Key findings include: evolution of npm supply-chain attacks with wormable malware and CI/CD persistence; active regional activity by threat cluster TGR-STA-1030; frontier AI enabling autonomous multi-stage/cloud attacks and faster vulnerability discovery; Wi‑Fi AirSnitch attacks that bypass WPA2/3 and client isolation; exploitation attempts against TP‑Link routers via CVE-2023-33538 with Mirai-like payloads; critical weaknesses in Amazon Bedrock AgentCore (overpriv­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
635593a09240e1b7fef64bd0cd4fe3ce3b933d2a5295cbe3305fda01f59269c4
Enrichment time
2026-04-25T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.