Also known as: tracked as, tools, CVE-2026-46333, Replicating Marauder, UNC6780, PyPI, Docker Hub
A supply chain attack targeting the npm ecosystem was identified involving 14 malicious packages published under the alias vpmdhaj. These packages typosquat well-known OpenSearch, ElasticSearch, and DevOps libraries, executing malicious payloads through npm lifecycle hooks during installation. The attack deploys a two-stage credential harvesting operation that targets AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens. The malware queries AWS Instance Metadata Service, ECS task metadata, and enumerates AWS Secrets Manager across multiple regions. Two stager variants were observed: an HTTP-based C2 beacon and a stealthier version abusing the legitimate Bun runtime. The stolen credentials enable cloud lateral movement and downstream supply chain attacks through compromised npm maintainer identities, specifically targeting developers working with cloud and CI/CD infrastructure.
Targeted Sectors
Executive Summary
The vpmdhaj threat actor conducted a supply chain attack on the npm ecosystem, leveraging 14 malicious packages to harvest AWS credentials, HashiCorp Vault tokens, and other sensitive information. The attack enables cloud lateral movement and facilitates further supply chain attacks through compromised npm maintainer identities. This campaign primarily targets developers working with cloud and CI/CD infrastructure.
Goals & Targeting
The vpmdhaj threat actor's strategic objectives appear to be centered around gaining access to sensitive credentials and leveraging these to facilitate cloud lateral movement and further supply chain attacks. Their targeting profile suggests a specific interest in compromising developers working with cloud and CI/CD infrastructure, indicating that the actor seeks to exploit the trust and access inherent to these roles. By doing so, they can potentially disrupt or manipulate the development and deployment of software applications, ultimately undermining the security and integrity of the software supply chain.
Enhanced Description
The vpmdhaj threat actor is a sophisticated adversary that has been identified as the perpetrator of a significant supply chain attack targeting the npm ecosystem. This attack involved the publication of 14 malicious packages under the vpmdhaj alias, which were designed to typosquat well-known OpenSearch, ElasticSearch, and DevOps libraries. Upon installation, these packages execute malicious payloads through npm lifecycle hooks, ultimately deploying a two-stage credential harvesting operation. The primary objective of this operation is to steal sensitive credentials, including AWS credentials, HashiCorp Vault tokens, GitHub Actions secrets, and npm publish tokens. To achieve this, the malware queries the AWS Instance Metadata Service, ECS task metadata, and enumerates AWS Secrets Manager across multiple regions.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The vpmdhaj campaign is notable for its use of a supply chain attack vector to compromise the npm ecosystem. The actor's operational tempo appears to be characterized by a period of active malicious package publication, followed by potential exploitation and lateral movement within compromised environments. The focus on stealing credentials associated with cloud and CI/CD infrastructure suggests that the actor is interested in perpetuating downstream attacks, potentially targeting organizations that rely heavily on these technologies. Notable past operations may include the compromise of npm maintainer identities and the subsequent exploitation of these identities to further the actor's goals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on the vpmdhaj threat actor is limited, and therefore, the confidence assessment is moderate to low. While the attack vector and tactics employed by the actor are well-documented, there are significant gaps in knowledge regarding the actor's motivations, sophistication, and overall objectives. Further research and analysis are necessary to fully understand the scope and implications of the vpmdhaj campaign.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics