216.73.216.6

Malicious npm packages abuse dependency confusion to profile developer environments

· Published 30/05/2026 06:07 · Modified 02/06/2026 09:59

Export JSON

Essential information

Published
30/05/2026 06:07
Modified
02/06/2026 09:59
Tags
2026-05-30 ci/cd targeting credential-theft dependency confusion environment fingerprinting lifecycle hooks npm supply chain obfuscation reconnaissance payload
Related entities
7 observables, 20 techniques (mitre), 11 others

Description

Microsoft Threat Intelligence identified an active supply chain attack involving malicious npm packages that employ techniques. Between May 28-29, 2026, a threat actor using three maintainer aliases published malicious packages across nine organizational scopes that mirror real corporate namespaces. The packages execute obfuscated reconnaissance payloads through npm , collecting system information, environment variables, and developer credentials. All packages connect to the same command-and-control server and deploy a 17KB JavaScript dropper designed for . The campaign includes platform-specific payloads for Windows, macOS, and Linux, with CI/CD detection bypass capabilities. The architecture operates in reconnaissance-only mode but supports server-side toggling for full exploitation. Forensic analysis indicates all three accounts are operated by a single individual, evidenced by shared C2 infrastructure, identical hardcoded authentication toke...

External references