Researchers found hundreds of malicious packages in the npm repository of open-source JavaScript code, designed to steal personally identifiable information (PII) in a large-scale typosquatting attack against Microsoft Azure cloud users. The set of packages appeared earlier this week and steadily grew since then, from about 50 packages to more than 200. JFrog Security Research team said the attack was a targeted attack against the entire @azure npm scope, by an attacker that employed an automatic script to create accounts and upload malicious packages.”]
Source: https://threatpost.com/microsoft-azure-developers-pii-stealing-npm-packages/179096/