Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors vpmdhaj

Also known as: tracked as, tools, CVE-2026-46333, Replicating Marauder, UNC6780, PyPI, Docker Hub

Description

A supply chain attack targeting the npm ecosystem was identified involving 14 malicious packages published under the alias vpmdhaj. These packages typosquat well-known OpenSearch, ElasticSearch, and DevOps libraries, executing malicious payloads through npm lifecycle hooks during installation. The attack deploys a two-stage credential harvesting operation that targets AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens. The malware queries AWS Instance Metadata Service, ECS task metadata, and enumerates AWS Secrets Manager across multiple regions. Two stager variants were observed: an HTTP-based C2 beacon and a stealthier version abusing the legitimate Bun runtime. The stolen credentials enable cloud lateral movement and downstream supply chain attacks through compromised npm maintainer identities, specifically targeting developers working with cloud and CI/CD infrastructure.

Goals & Targeting

Targeted Sectors

Financial services
Hospitality
Aviation
Defense
Healthcare
Manufacturing
Energy

AI Analysis

· 2 weeks ago

Executive Summary

The vpmdhaj threat actor conducted a supply chain attack on the npm ecosystem, leveraging 14 malicious packages to harvest AWS credentials, HashiCorp Vault tokens, and other sensitive information. The attack enables cloud lateral movement and facilitates further supply chain attacks through compromised npm maintainer identities. This campaign primarily targets developers working with cloud and CI/CD infrastructure.

Goals & Targeting

The vpmdhaj threat actor's strategic objectives appear to be centered around gaining access to sensitive credentials and leveraging these to facilitate cloud lateral movement and further supply chain attacks. Their targeting profile suggests a specific interest in compromising developers working with cloud and CI/CD infrastructure, indicating that the actor seeks to exploit the trust and access inherent to these roles. By doing so, they can potentially disrupt or manipulate the development and deployment of software applications, ultimately undermining the security and integrity of the software supply chain.

Enhanced Description

The vpmdhaj threat actor is a sophisticated adversary that has been identified as the perpetrator of a significant supply chain attack targeting the npm ecosystem. This attack involved the publication of 14 malicious packages under the vpmdhaj alias, which were designed to typosquat well-known OpenSearch, ElasticSearch, and DevOps libraries. Upon installation, these packages execute malicious payloads through npm lifecycle hooks, ultimately deploying a two-stage credential harvesting operation. The primary objective of this operation is to steal sensitive credentials, including AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens. To achieve this, the malware queries the AWS Instance Metadata Service, ECS task metadata, and enumerates AWS Secrets Manager across multiple regions.

Key Capabilities

  • Supply chain attack execution
  • Typosquatting and namespace hijacking
  • Credential harvesting and theft
  • Cloud lateral movement and exploitation
  • Abuse of legitimate software and services

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1041
T1552.001
T1204

Software / Tooling

Custom malware
Bun runtime
npm package manager

Campaigns & Victims

The vpmdhaj campaign is notable for its use of a supply chain attack vector to compromise the npm ecosystem. The actor's operational tempo appears to be characterized by a period of active malicious package publication, followed by potential exploitation and lateral movement within compromised environments. The focus on stealing credentials associated with cloud and CI/CD infrastructure suggests that the actor is interested in perpetuating downstream attacks, potentially targeting organizations that rely heavily on these technologies. Notable past operations may include the compromise of npm maintainer identities and the subsequent exploitation of these identities to further the actor's goals.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Typosquatting and namespace hijacking of npm packages
  • Abuse of legitimate Bun runtime

Recommended Actions

  • Implement robust npm package validation and vetting procedures
  • Monitor for and block suspicious npm package installation activity
  • Enforce least privilege access for npm maintainers and CI/CD pipeline operators
  • Regularly audit and rotate sensitive credentials, including AWS credentials and HashiCorp Vault tokens
  • Utilize runtime application self-protection (RASP) and other anti-tamper technologies to detect and prevent malicious code execution

Suggested Tags

Supply Chain Attack
Credential Harvesting
Cloud Lateral Movement
npm Ecosystem
CI/CD Infrastructure

Confidence Assessment

The available data on the vpmdhaj threat actor is limited, and therefore, the confidence assessment is moderate to low. While the attack vector and tactics employed by the actor are well-documented, there are significant gaps in knowledge regarding the actor's motivations, sophistication, and overall objectives. Further research and analysis are necessary to fully understand the scope and implications of the vpmdhaj campaign.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 2 Domain 11 Filename 5 Email Address 2

References

  1. thehackernews.com — Cited by web research for: Replicating Marauder
  2. www.microsoft.com — Cited by web research for: Payload
  3. www.malwarebytes.com — Cited by web research for: Dark
  4. gbhackers.com — Cited by web research for: WhatsApp
  5. www.bleepingcomputer.com — Cited by web research for: STOP
  6. cybersecuritynews.com — Cited by web research for: Telegram

Intel Summary

0

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Supply Chain Attack
Phishing
Backdoor / C2

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
May 29, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.