Typosquatted npm Packages Steal Cloud and CI/CD Secrets
ID: 13c1d355-e523-5007-a21b-7e43fed045cf
STIX ID: report--13c1d355-e523-5007-a21b-7e43fed045cf
Feed Name: GBHackers
A coordinated npm supply-chain campaign used typosquatted and lookalike packages (published by an actor using the alias “vpmdhaj”) to silently execute preinstall scripts that deploy a two-stage payload capable of harvesting AWS credentials, Vault tokens, GitHub Actions secrets, and npm publish tokens; later variants use a Bun runtime loader to reduce noisy outbound C2 traffic and persist by relaunching when the module is imported. The report provides indicators of compromise, describes persistence and credential-exfiltration techniques, documents removal of malicious packages from npm, and recommends credential rotation, auditing dependencies, disabling npm install scripts, and network monitoring for artifacts such as the “X-Supply:1” header.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
