Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Typosquatted npm packages used to steal cloud and CI/CD secrets

aab.sportsontheweb.net

TLP:CLEAR
Active

Domain

Description

A supply chain attack targeting the npm ecosystem was identified involving 14 malicious packages published under the alias vpmdhaj. These packages typosquat well-known OpenSearch, ElasticSearch, and DevOps libraries, executing malicious payloads through npm lifecycle hooks during installation. The attack deploys a two-stage credential harvesting operation that targets AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens. The malware queries AWS Instance Metadata Service, ECS task metadata, and enumerates AWS Secrets Manager across multiple regions. Two stager variants were observed: an HTTP-based C2 beacon and a stealthier version abusing the legitimate Bun runtime. The stolen credentials enable cloud lateral movement and downstream supply chain attacks through compromised npm maintainer identities, specifically targeting developers working with cloud and CI/CD infrastructure.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Typosquatted npm packages used to steal cloud and CI/CD secrets
Pattern Type
STIX
Confidence
75%
Valid From
May 29, 2026 21:09
Total Sightings
0
Added
May 29, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of aab.sportsontheweb.net

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.