The npm Threat Landscape: Attack Surface and Mitigations
2026-04-25T08:51:47Z•635593a09240e1b7fef64bd0cd4fe3ce3b933d2a5295cbe3305fda01f59269c4
AWS-BedrockAgentCoreAirSnitchAxios-supply-chainCI/CD-persistenceCVE-2023-33538DNS-tunnelingIAM-privilege-escalationKubernetesMiraiTGR-STA-1030','Iran-cyberactivity','frontier-AI','autonomous-attTP-LinkTeamPCPVect-ransomwareVertex-AIWiFi-bypasscloud-securitycredential-exposuremalwaremulti-agentnpmprompt-injectionsandbox-escapesupply-chainwormable-malware
What happened
Unit 42 published multiple research posts covering elevated threats across supply chains, cloud/A I platforms, IoT, and wireless. Key findings include: evolution of npm supply-chain attacks with wormable malware and CI/CD persistence; active regional activity by threat cluster TGR-STA-1030; frontier AI enabling autonomous multi-stage/cloud attacks and faster vulnerability discovery; Wi‑Fi AirSnitch attacks that bypass WPA2/3 and client isolation; exploitation attempts against TP‑Link routers via CVE-2023-33538 with Mirai-like payloads; critical weaknesses in Amazon Bedrock AgentCore (overpriv
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 635593a09240e1b7fef64bd0cd4fe3ce3b933d2a5295cbe3305fda01f59269c4
- Enrichment time
- 2026-04-25T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.