Massive npm Dependency Confusion Attack Infiltrates Corporate Ecosystems
ID: 99fe1919-bcf6-59d0-93b9-5f06db89d7f2
STIX ID: report--99fe1919-bcf6-59d0-93b9-5f06db89d7f2
Feed Name: securityonline.info
Microsoft Threat Intelligence uncovered an active npm dependency confusion campaign where a single operator published dozens of rogue packages impersonating internal organizational scopes to execute obfuscated postinstall hooks that retrieve a reconnaissance payload; the attacker used inflated version numbers, spoofed internal URLs, and a shared hardcoded X-Secret header (l95HdDaz3kQx1Zsg3WxH6HvKANf51RY1) across three maintainer accounts, and the report recommends auditing lockfiles, disabling install scripts, and blocking the domain `oob.moika.tech`.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
