MAL-2026-3322

    Dashboard / Malicious Package / MAL-2026-3322

    MAL-2026-3322

    Published: 4 May 2026Last Modified: 12 May 2026

    Summary: Malicious code in microsoft-agents-auth-service (npm)

    Details: Malicious npm package published by the `microsop` threat actor as part of a dependency-confusion campaign that impersonates internal tooling at Microsoft, Google Cloud, and PayPal using inflated semver values (e.g. 99.9.x, 100.1.x) to win npm resolution against private internal packages. All packages in the campaign falsely advertise themselves as "Security Research PoC" / MSRC research and execute on `preinstall` via `node index.js`, exfiltrating to disposable `webhook.site` endpoints. This package targets Microsoft-internal infrastructure. On install it shells out to harvest `/etc/passwd`, probe `/etc/shadow`, locate SSH private keys (`id_rsa`, `*.pem`, `authorized_keys`), enumerate `.netrc` / `.dockercfg`, query the AWS IMDS endpoint `http://169.254.169.254/latest/user-data`, and grep environment variables matching `USER|PASS|TOKEN|CREDENTIAL`. The collected output is POSTed to `https://webhook.site/11b6a711-bdc7-4444-9a0e-ffcb23151e82` tagged `status: ULTRA_USER_CREDENTIAL_SCOUT`, `target: global-microsoft-infra`. Source: amazon-inspector (bef9025a8049b8baa13cd6339e3f0eaed86f5ecaf0d21e053fe88ae0f6014480) The package microsoft-agents-auth-service was found to contain malicious code.

    References:

    Affected packages

    Package

    Name: microsoft-agents-auth-service

    Purl: pkg:npm/microsoft-agents-auth-service

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2026-3322 | CVE-DB