Dependency Confusion Campaign Shows Reconnaissance Is the First Supply-Chain Payload
Microsoft found 33 malicious npm packages abusing dependency confusion to profile developer and build environments. The defender lesson: treat package installation as code execution and lock down internal namespace hygiene before attackers do reconnaissance at scale.
