Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Between May 20 and May 29, 2026, Microsoft Threat Intelligence identified three coordinated npm supply chain campaigns delivering malicious packages through dependency confusion, typosquatting, and a compromised publisher account. All three campaigns silently harvest AWS credentials, HashiCorp Vault tokens, GitHub Actions tokens, and npm publish tokens from developer workstations and CI/CD pipelines at install time. Any organization running Node.js build pipelines or using affected packages faces immediate risk of cloud infrastructure takeover and CI/CD pipeline compromise.

Author

Tech Jacks Solutions