The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)
2026-06-02T20:51:39Z•8c36f3e58a78dcbdbbbdc99cc06265a92f05ae04910880f71ca182741b333381
AD CS exploitationAI browser extensions data exfiltration','cyber extortion','ramsAPTActive Directory Certificate ServicesAppDomainManager hijackCI/CD persistenceCVE-2026-0300CVE-2026-31431Copy FailFlutterShellGremlin stealerLinux kernel LPEPAN-OS captive portalRATROADtoolsScreening SerpensTamperedChefbackdoorcloud intrusionmacOS malvertisingnpm supply chainsupply chain attackstrojanized appswormable malwarezero-day
What happened
Palo Alto Unit 42 published a collection of threat research and advisories covering active and emerging risks: npm supply‑chain evolution with wormable malware, CI/CD persistence and multi‑stage attacks; a macOS malvertising campaign (Operation FlutterBridge) distributing a new Flutter‑based backdoor (FlutterShell); Iranian APT Screening Serpens espionage using AppDomainManager hijacking and new RATs; misuse of the open‑source ROADtools framework for cloud intrusions; TamperedChef clusters delivered via trojanized productivity apps and malvertising; the evolution of Gremlin stealer with novel‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 8c36f3e58a78dcbdbbbdc99cc06265a92f05ae04910880f71ca182741b333381
- Enrichment time
- 2026-06-02T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.