MAL-2026-3322
Dashboard / Malicious Package / MAL-2026-3322
MAL-2026-3322
Summary: Malicious code in microsoft-agents-auth-service (npm)
Details: Malicious npm package published by the `microsop` threat actor as part of a dependency-confusion campaign that impersonates internal tooling at Microsoft, Google Cloud, and PayPal using inflated semver values (e.g. 99.9.x, 100.1.x) to win npm resolution against private internal packages. All packages in the campaign falsely advertise themselves as "Security Research PoC" / MSRC research and execute on `preinstall` via `node index.js`, exfiltrating to disposable `webhook.site` endpoints. This package targets Microsoft-internal infrastructure. On install it shells out to harvest `/etc/passwd`, probe `/etc/shadow`, locate SSH private keys (`id_rsa`, `*.pem`, `authorized_keys`), enumerate `.netrc` / `.dockercfg`, query the AWS IMDS endpoint `http://169.254.169.254/latest/user-data`, and grep environment variables matching `USER|PASS|TOKEN|CREDENTIAL`. The collected output is POSTed to `https://webhook.site/11b6a711-bdc7-4444-9a0e-ffcb23151e82` tagged `status: ULTRA_USER_CREDENTIAL_SCOUT`, `target: global-microsoft-infra`. Source: amazon-inspector (bef9025a8049b8baa13cd6339e3f0eaed86f5ecaf0d21e053fe88ae0f6014480) The package microsoft-agents-auth-service was found to contain malicious code.
References:
Affected packages
Package
Name: microsoft-agents-auth-service
Purl: pkg:npm/microsoft-agents-auth-service
Affected ranges
Type: SEMVER
Events:
