Supply Chain Attack
Microsoft Names 33 Malicious npm Packages in a Dependency-Confusion Recon Campaign
Microsoft Threat Intelligence disclosed 33 malicious npm packages published under three aliases attributed to a single operator. The packages abuse dependency confusion to fingerprint developer and build environments and ship a server-toggled reconnaissance payload.