Microsoft reports a dependency confusion campaign leveraging 33 malicious npm packages to gather reconnaissance data on developer and build environments. The post details the attack chain, methods used by attackers, and ways to detect such activities.