Microsoft Threat Intelligence has identified a sophisticated supply chain attack using malicious npm packages to perform reconnaissance on corporate environments through dependency confusion and obfuscated payloads.
Key Points
- Attackers published malicious packages across nine organizational scopes between May 28 and May 29, 2026, impersonating legitimate internal enterprise infrastructure.
- The campaign utilized three npm maintainer accounts—mr.4nd3r50n, ce-rwb, and t-in-one—to distribute packages that execute obfuscated reconnaissance scripts during installation.
- Malicious code automatically collects system information, environment variables, and developer context, sending data to a command-and-control server at oob.moika[.]tech.
- The attack architecture includes a "reconnaissance-only" mode, allowing the operator to identify high-value targets for potential future exploitation.
- Microsoft has confirmed the malicious repositories were removed from the npm registry following forensic investigation and reporting.