Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Typosquatted npm packages used to steal cloud and CI/CD secrets

0
Medium
Published: Fri May 29 2026 (05/29/2026, 06:11:38 UTC)
Source: AlienVault OTX General

Description

A supply chain attack involving 14 malicious npm packages published under the alias vpmdhaj was identified. These packages typosquat popular OpenSearch, ElasticSearch, and DevOps libraries and execute malicious payloads during installation via npm lifecycle hooks. The attack harvests AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens by querying AWS metadata services and enumerating AWS Secrets Manager. Two variants of the malware stager exist: one using an HTTP-based command and control beacon and another abusing the Bun runtime for stealth. The stolen credentials facilitate cloud lateral movement and further supply chain compromises by hijacking npm maintainer identities, targeting developers working with cloud and CI/CD infrastructure. No official patch or remediation guidance is provided in the available data.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/29/2026, 11:03:46 UTC

Technical Analysis

This campaign targets the npm ecosystem through typosquatting, where 14 malicious packages impersonate well-known OpenSearch, ElasticSearch, and DevOps libraries. Upon installation, these packages execute malicious code via npm lifecycle hooks to perform a two-stage credential harvesting operation. The malware collects AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens by querying AWS Instance Metadata Service, ECS task metadata, and enumerating AWS Secrets Manager across multiple regions. Two stager variants were observed: an HTTP-based command and control beacon and a stealthier variant abusing the legitimate Bun runtime. The harvested credentials enable attackers to move laterally within cloud environments and conduct downstream supply chain attacks by compromising npm maintainer identities, specifically targeting developers involved with cloud and CI/CD workflows.

Potential Impact

The attack compromises sensitive cloud and CI/CD secrets including AWS credentials, Vault tokens, GitHub Actions secrets, and npm publish tokens. This enables attackers to perform lateral movement within cloud environments and potentially compromise additional supply chain components by abusing npm maintainer identities. The malicious packages can lead to unauthorized access and control over cloud infrastructure and developer workflows, increasing the risk of further downstream attacks.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until official fixes or removals are available, developers should avoid installing suspicious or typosquatted npm packages, verify package names carefully, and use tools that detect typosquatting and malicious packages. Monitoring for unusual activity related to npm tokens and cloud credentials is recommended. Employing least privilege principles for CI/CD secrets and rotating credentials regularly can reduce impact. Refer to the Microsoft security blog linked in the technical details for updated guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/05/28/typosquatted-npm-packages-used-steal-cloud-ci-cd-secrets/"]
Adversary
vpmdhaj
Pulse Id
6a192e1ac095630ef4d5d60f
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash106bc56415ee087c8a432b2f0f90aa2d
hashddd329f1e009abbab39199d6362d2b340c96e41a
hash638788afc4f1b5860a328312caf5895abd5f5632d28a4f2a85b09076e270d15d
hash77d92efe7af3547f71fd41d4a884872d66b1be9499eaa637e91eac866911694d
hashbfa149694ec6411c23936311a999163ade54d6f38e2f4b0e3cfb8cb67bd7cfaa

Url

ValueDescriptionCopy
urlhttp://aab.sportsontheweb.net/x.php

Domain

ValueDescriptionCopy
domainaab.sportsontheweb.net

Threat ID: 6a196f02e29bf47b50db4440

Added to database: 5/29/2026, 10:48:34 AM

Last enriched: 5/29/2026, 11:03:46 AM

Last updated: 5/29/2026, 7:28:31 PM

Views: 42

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses