The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)

2026-06-02T20:51:39Z8c36f3e58a78dcbdbbbdc99cc06265a92f05ae04910880f71ca182741b333381
AD CS exploitationAI browser extensions data exfiltration','cyber extortion','ramsAPTActive Directory Certificate ServicesAppDomainManager hijackCI/CD persistenceCVE-2026-0300CVE-2026-31431Copy FailFlutterShellGremlin stealerLinux kernel LPEPAN-OS captive portalRATROADtoolsScreening SerpensTamperedChefbackdoorcloud intrusionmacOS malvertisingnpm supply chainsupply chain attackstrojanized appswormable malwarezero-day

What happened

Palo Alto Unit 42 published a collection of threat research and advisories covering active and emerging risks: npm supply‑chain evolution with wormable malware, CI/CD persistence and multi‑stage attacks; a macOS malvertising campaign (Operation FlutterBridge) distributing a new Flutter‑based backdoor (FlutterShell); Iranian APT Screening Serpens espionage using AppDomainManager hijacking and new RATs; misuse of the open‑source ROADtools framework for cloud intrusions; TamperedChef clusters delivered via trojanized productivity apps and malvertising; the evolution of Gremlin stealer with novel‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
8c36f3e58a78dcbdbbbdc99cc06265a92f05ae04910880f71ca182741b333381
Enrichment time
2026-06-02T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2) · Baitaphish