logo

Typosquatted npm Packages Steal Cloud and CI/CD Secrets

ID: 13c1d355-e523-5007-a21b-7e43fed045cf

STIX ID: report--13c1d355-e523-5007-a21b-7e43fed045cf

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Mayura Kathir

...
...

A coordinated npm supply-chain campaign used typosquatted and lookalike packages (published by an actor using the alias “vpmdhaj”) to silently execute preinstall scripts that deploy a two-stage payload capable of harvesting AWS credentials, Vault tokens, GitHub Actions secrets, and npm publish tokens; later variants use a Bun runtime loader to reduce noisy outbound C2 traffic and persist by relaunching when the module is imported. The report provides indicators of compromise, describes persistence and credential-exfiltration techniques, documents removal of malicious packages from npm, and recommends credential rotation, auditing dependencies, disabling npm install scripts, and network monitoring for artifacts such as the “X-Supply:1” header.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.