For the 2nd time in weeks, #Microsoft packages laced with #credential stealer

Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.

In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
#security

https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/

For the 2nd time in weeks, Microsoft packages laced with credential stealer

73 packages run self-replicating stealer as soon as they're opened by an AI agent.

Ars Technica

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealingcampaign - https://www.redpacketsecurity.com/preinstall-to-persistence-inside-the-red-hat-npm-miasma-credential-stealingcampaign/

#threatintel
#npm-supply-chain
#credential-theft
#Miasma
#supply-chain-security
#redhat-cloud-services

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealingcampaign - RedPacket Security

Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 32 maliciously modified packages across more than 90 versions under

RedPacket Security
Typosquatted npm packages used to steal cloud and CI/CD secrets - RedPacket Security

Microsoft has identified an active supply chain attack targeting the npm package ecosystem. On May 28, 2026, a single threat actor operating under the newly

RedPacket Security

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5and Confluence - https://www.redpacketsecurity.com/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5and-confluence/

#threatintel
#edge-appliances
#linux-intrusion
#confluence
#credential-relay
#mitre-attack-techniques

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5and Confluence - RedPacket Security

A growing trend in modern intrusions is the compromise of internet-facing edge appliances such as firewalls and VPN gateways. Systems traditionally deployed

RedPacket Security

Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft - https://www.redpacketsecurity.com/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/

#threatintel
#antv
#npm-supply-chain
#github-actions
#credential-theft
#supply-chain-security

Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft - RedPacket Security

Microsoft has identified an active supply chain attack targeting the @antv node package manager (npm) package ecosystem. A threat actor compromised an @antv

RedPacket Security

Undermining the trust boundary: Investigating a stealthy intrusion throughthird-party compromise - https://www.redpacketsecurity.com/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-throughthird-party-compromise/

#threatintel
#trusted-relationships
#third-party-risk
#credential-theft
#persistence
#intrusion-detection

Undermining the trust boundary: Investigating a stealthy intrusion throughthird-party compromise - RedPacket Security

In recent years, many sophisticated intrusions have increasingly avoided using noisy exploits, obvious malware, or custom tooling, instead leveraging systems

RedPacket Security

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTMtoken compromise - https://www.redpacketsecurity.com/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitmtoken-compromise/

#threatintel
#aiTM-phishing
#credential-theft
#phishing-attack
#adversary-in-the-middle
#cybersecurity-awareness

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTMtoken compromise - RedPacket Security

Phishing campaigns continue to improve sophistication and refinement in blending social engineering, delivery and hosting infrastructure, and authentication

RedPacket Security

Containing a domain compromise: How predictive shielding shut down lateralmovement - https://www.redpacketsecurity.com/containing-a-domain-compromise-how-predictive-shielding-shut-down-lateralmovement/

#threatintel
#Predictive Shielding
#Domain Compromise
#Credential-Based Attacks
#Active Directory Security
#Incident Response

Containing a domain compromise: How predictive shielding shut down lateralmovement - RedPacket Security

In identity-based attack campaigns, any initial access activity can turn an already serious intrusion into a critical incident once it allows a threat actor

RedPacket Security
Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise - RedPacket Security

Executive summary

RedPacket Security

Thousands of consumer #routers hacked by Russia's #military

The Russian military is once again #hacking home and small office routers in widespread operations that send unwitting users to sites that harvest #passwords and #credential tokens for use in #espionage campaigns, researchers said Tuesday.
#russia #security #privacy #gru

https://arstechnica.com/security/2026/04/russias-military-hacks-thousands-of-consumer-routers-to-steal-credentials/

Thousands of consumer routers hacked by Russia's military

End-of-life routers in homes and small offices hacked in 120 countries.

Ars Technica