PULSE NAME
Typosquatted npm packages used to steal cloud and CI/CD secrets
WHITE vpmdhaj AlienVault 2026-05-29 Modified: 2026-05-29
7
IOCs
LOW VOLUME
A supply chain attack targeting the npm ecosystem was identified involving 14 malicious packages published under the alias vpmdhaj. These packages typosquat well-known OpenSearch, ElasticSearch, and DevOps libraries, executing malicious payloads through npm lifecycle hooks during installation. The attack deploys a two-stage credential harvesting operation that targets AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens. The malware queries AWS Instance Metadata Service, ECS task metadata, and enumerates AWS Secrets Manager across multiple regions. Two stager variants were observed: an HTTP-based C2 beacon and a stealthier version abusing the legitimate Bun runtime. The stolen credentials enable cloud lateral movement and downstream supply chain attacks through compromised npm maintainer identities, specifically targeting developers working with cloud and CI/CD infrastructure.
Indicators of Compromise (7)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 106bc56415ee087c8a432b2f0f90aa2d 2026-05-29
FileHash-SHA1 ddd329f1e009abbab39199d6362d2b340c96e41a 2026-05-29
FileHash-SHA256 638788afc4f1b5860a328312caf5895abd5f5632d28a4f2a85b09076e270d15d 2026-05-29
FileHash-SHA256 77d92efe7af3547f71fd41d4a884872d66b1be9499eaa637e91eac866911694d 2026-05-29
FileHash-SHA256 bfa149694ec6411c23936311a999163ade54d6f38e2f4b0e3cfb8cb67bd7cfaa 2026-05-29
URL http://aab.sportsontheweb.net/x.php 2026-05-29
hostname aab.sportsontheweb.net 2026-05-29