Topics
Follow your own topics →
DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

security: Malicious npm packages abuse dependency confusion to profile developer environments

119 · Sujith Quintelier · May 30, 2026, 6:01 a.m.
Security NPM Packages Dependency Confusion malware
Summary
Microsoft reports a dependency confusion campaign leveraging 33 malicious npm packages to gather reconnaissance data on developer and build environments. The post details the attack chain, methods used by attackers, and ways to detect such activities.
Read full post on quintelier.dev →
MORE POSTS LIKE THIS
NPM Package Tests AI Malware Scanner Evasion
Securityonline · Jun 21, 2026
malware AI Malware
AUR Registrations Blocked Amid Ongoing Malware Mess
Fossforce · Jun 16, 2026
Distros Security
pip v26.1 adds support for relative dependency cooldowns
cclauss · Apr 27, 2026
pip v26.1 Python
Open Source Malware with Paul McCarty
Opensourcesecurity · Apr 13, 2026
Open Source malware
The Axios supply chain attack used individually targeted social engineering
simonw · Apr 3, 2026
Open Source packaging
crates.io: Malicious crates evm-units and uniswap-utils
The Rust Programming Language · Dec 3, 2025
Security cryptocurrency
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google