July 16, 2026

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

In this article Attack chain overview How the attack started: GitHub Actions pwn request Mitigation and protection guidance Learn more On July 14, 2026, Microsoft Threat […]
June 18, 2026

From package to postinstall payload: Inside the Mastra npm supply chain compromise

In this article Attack chain overview Discovery and initial indicators Dependency injection: the poisoned package.json Typosquat analysis: easy-day-js Staged delivery pattern Obfuscation and payload analysis TLS […]
June 3, 2026

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

In this article Attack chain overview Mitigation and protection guidance Learn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 32 maliciously modified […]
May 30, 2026

Malicious npm packages abuse dependency confusion to profile developer environments

In this article Attack chain overview Threat actor attribution Mitigation and protection guidance Indicators of Compromise (IOC) References Learn more Microsoft Threat Intelligence has uncovered an […]