logo

Massive npm Dependency Confusion Attack Infiltrates Corporate Ecosystems

ID: 99fe1919-bcf6-59d0-93b9-5f06db89d7f2

STIX ID: report--99fe1919-bcf6-59d0-93b9-5f06db89d7f2

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Ddos

...
...

Microsoft Threat Intelligence uncovered an active npm dependency confusion campaign where a single operator published dozens of rogue packages impersonating internal organizational scopes to execute obfuscated postinstall hooks that retrieve a reconnaissance payload; the attacker used inflated version numbers, spoofed internal URLs, and a shared hardcoded X-Secret header (l95HdDaz3kQx1Zsg3WxH6HvKANf51RY1) across three maintainer accounts, and the report recommends auditing lockfiles, disabling install scripts, and blocking the domain `oob.moika.tech`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.