Back to Intel

Intel Node

Malicious npm packages abuse dependency confusion to profile developer environments

lowapt2026-05-30T00:06:20+00:00source excerpt
apttradecraftdetectionwindowslinux

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and disrupt related activity. The post Malicious npm packages abuse dependency confusion to profile developer environments appeared first on Microsoft Security Blog .

In this article Attack chain overview Threat actor attribution Mitigation and protection guidance Indicators of Compromise (IOC) References Learn more Microsoft Threat Intelligence has uncovered an active supply chain attack involving malicious npm packages registered under organizational scopes that mirror real internal corporate namespaces, employing dependency confusion technique to deploy an obfuscated reconnaissance payload. On May 28 and May 29, 2026, a threat actor operating under three maintainer aliases mr. 4nd3r50n ( mr. 4nd3r50n@yandex[. ]ru ), ce-rwb ( ogvanta@yandex[. ]ru ), and t-in-one ( t-in-one@yandex[.

]ru ) published malicious packages across two publishing bursts.

Read Original Source