Observed Signal · Jun 9, 2026 · Security Incident · Source: DEV Community · Impact: 5/5 · Sentiment: Negative

Microsoft npm Packages Backdoored; AI Agents Trigger Credential Stealer

Executive Signal Summary

Seventy-three cryptographically signed Microsoft npm packages were compromised with a credential‑stealing worm called “Miasma,” derived from an open-source toolkit. The malware deploys a small (≈28 KB) payload that automatically harvests credentials from cloud providers (AWS, Azure, GCP), Kubernetes, many developer tool configs and password managers, and then spreads laterally through cloud infrastructure. The payload is triggered simply by opening a package inside AI coding agents and IDE integrations (examples named: Claude Code, Gemini CLI, Cursor, VS Code). Attackers used stolen Microsoft publisher credentials to publish malicious builds that carried valid SLSA provenance attestations, defeating provenance-only detection. The same Microsoft account had previously been compromised in May 2026 (durabletask Python SDK on PyPI), raising concerns about credential rotation and remediation.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A large-scale supply‑chain compromise of Microsoft-signed packages that abused SLSA provenance and uses AI agents as a trigger expands the developer attack surface and undermines trust in provenance controls — a high-impact industry security event.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • 73 official Microsoft npm packages were poisoned with the Miasma worm.
  • Miasma executes automatically when a package is opened inside AI coding agents or IDE agent layers.
  • The payload (~28 KB) harvests credentials from AWS, Azure, GCP, Kubernetes, 90+ developer tool configs, and password managers and spreads laterally.
  • Attack vector: stolen Microsoft publisher credentials → malicious builds published with valid SLSA provenance attestation, bypassing provenance-only scanners.
  • The same Microsoft account was previously compromised in May 2026 (durabletask Python SDK on PyPI), indicating incomplete remediation or a second credential theft.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jun 9, 2026
Original Coverage Title: “Microsoft's npm Packages Got Backdoored. Again. And AI Agents Pulled the Trigger.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security / Supply Chain (LLM & Developer Tooling)Jun 20, 2026

North Korean Hackers Poisoned 140+ npm Packages

Microsoft attributed a supply-chain attack on the Mastra AI ecosystem to Sapphire Sleet (also tracked as BlueNoroff), in which attackers poisoned over 140 npm packages that AI coding assistants and developer tooling actively surface. The incident is notable because LLM-backed IDE assistants (e.g., Copilot, Cursor) can suggest or auto-install dependencies, allowing malicious code to reach developer machines without traditional phishing. Microsoft’s public details are limited: a state-level actor, 140+ contaminated packages, and a focus on AI-assisted development workflows. The article highlights detection gaps—npm audit relies on published CVEs, lockfiles help only post-install, and LLMs do not validate package provenance—and describes Sentinel’s SlopScan integration as a defensive pattern that extracts package names from LLM output and flags or blocks suspicious packages before installation. Publication date: 2026-06-20.

Read assessment
Supply Chain AttackJun 8, 2026

Microsoft GitHub Repos Injected with Password-Stealing Malware

Microsoft disabled access to dozens of its open-source GitHub repositories after security researchers flagged malware injected into project code that steals passwords and credentials when developers open the compromised tools in AI coding apps. Affected projects include Azure-related tools and developer integrations for AI coding environments such as Claude Code, Google’s Gemini CLI and VS Code. Security firms Cloudsmith and OpenSourceMalware were among the first to report the incident. At least 70 Microsoft-owned repositories were marked disabled on GitHub. The incident appears related to a recent mid-May compromise of Microsoft’s Durable Task project and has been described by researchers as a potential re-compromise or follow-on breach.

Read assessment
Security / Software Supply ChainJun 17, 2026

144 Mastra npm Packages Compromised in Supply-Chain Attack

In June 2026, attackers hijacked an npm contributor account (ehindero) and mass-published malicious versions of 144 packages in the @mastra namespace in an incident dubbed the easy-day-js supply-chain attack. Security researchers from JFrog, SafeDep, Socket and StepSecurity jointly uncovered the breach. Mastra is a popular open-source JavaScript/TypeScript framework used for AI application development, so the compromise risks propagating malicious code into many downstream projects and AI workloads. Researchers recommend immediate automated dependency audits, removal or rollback of affected packages, credential rotation, enforcing multi-factor authentication for publishers, and continuous monitoring via supply-chain scanning tools (e.g., JFrog Xray, Socket, SafeDep). The incident underscores account-level contributor access as a major attack surface for npm and similar registries, and calls for stronger registry-level publisher controls and provenance checks.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.