All updates
security: Malicious npm packages abuse dependency confusion to profile developer environments
May 30, 2026
Microsoft reports a dependency confusion campaign using 33 malicious npm packages to collect reconnaissance data from developer and build environments. The post outlines the attack chain, attacker tradecraft, and detection opportunities for identifying related activity.
- Source: Microsoft Security Blog