AUTO-UPDATED

Malicious npm packages abuse dependency confusion to profile developer environments

Microsoft Threat Intelligence has identified a sophisticated supply chain attack using malicious npm packages to perform reconnaissance on corporate environments through dependency confusion and obfuscated payloads.

Key Points

  • Attackers published malicious packages across nine organizational scopes between May 28 and May 29, 2026, impersonating legitimate internal enterprise infrastructure.
  • The campaign utilized three npm maintainer accounts—mr.4nd3r50n, ce-rwb, and t-in-one—to distribute packages that execute obfuscated reconnaissance scripts during installation.
  • Malicious code automatically collects system information, environment variables, and developer context, sending data to a command-and-control server at oob.moika[.]tech.
  • The attack architecture includes a "reconnaissance-only" mode, allowing the operator to identify high-value targets for potential future exploitation.
  • Microsoft has confirmed the malicious repositories were removed from the npm registry following forensic investigation and reporting.

Why it Matters

This campaign demonstrates a high level of sophistication by mimicking internal corporate namespaces to trick developers into installing malicious dependencies. Organizations should audit their CI/CD pipelines and developer environments for these packages to prevent potential credential theft and unauthorized system access.
Microsoft.com Published by Microsoft Defender Security Research Team
Read original