Typosquatted npm packages used to steal cloud and CI/CD secrets
ID: 54de1827-ec7a-5988-b88b-5a97c83ddf27
STIX ID: report--54de1827-ec7a-5988-b88b-5a97c83ddf27
Feed Name: Microsoft Security
Date Published: 2026-05-29
Date Updated: 2026-05-29
Author: Microsoft Defender Security Research Team
Microsoft observed an active npm supply-chain campaign (published 2026-05-28) by maintainer alias vpmdhaj that published 14 typosquat packages mimicking OpenSearch/Elastic libraries. Packages use npm lifecycle hooks to execute a two-stage loader (Gen‑1 HTTP C2 or Gen‑2 Bun runtime abuse) and drop a ~195 KB Bun-compiled credential harvester that exfiltrates AWS credentials (IMDSv2, ECS task roles, Secrets Manager), HashiCorp Vault tokens, npm publish tokens, and GitHub Actions secrets; IOCs, detection queries, and mitigation guidance (including ignore-scripts, token rotation, and Defender/XDR detections) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
