Threat reportSupply ChainTL-2026-0623
vpmdhaj npm Supply Chain Attack — 14 OpenSearch/ElasticSearch Typosquats Steal AWS/Vault/CI-CD Secrets via Bun-Compiled Stager (Mini Shai-Hulud)
vpmdhaj npm Supply Chain Attack (TL-2026-0623), also tracked as Mini Shai-Hulud, is a high-severity supply-chain compromise, first published 2026-05-29. It has no confirmed attribution, affects npm (actor: vpmdhaj) Malicious typosquat packages, maps to 19 MITRE ATT&CK techniques (T1027, T1027.004, T1036), and is covered by 9 detection rules and 42 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 42Indicators of compromise
Key facts for TL-2026-0623
- Threat ID
- TL-2026-0623
- Also known as
- Mini Shai-Hulud, vpmdhaj typosquat campaign
- Severity
- HIGH
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, devops, cloud-services, financial-services
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 42
Malware and tooling in vpmdhaj npm Supply Chain Attack
Malware and tooling: Backdoor:JS/SupplyChain, Trojan:JS/ObfusNpmJs, Trojan:JS/ShaiWorm, Bun runtime (legitimate, abused)
How vpmdhaj npm Supply Chain Attack works
A single actor under the new npm alias "vpmdhaj" published 14 typosquatted OpenSearch/ElasticSearch/DevOps packages on 2026-05-28 whose npm install-time lifecycle hooks run a ~195 KB Bun-compiled credential harvester. The stager steals AWS credentials (IMDSv2, ECS task roles, Secrets Manager across 16+ regions), HashiCorp Vault tokens, npm publish tokens, and GitHub Actions context, exfiltrating over HTTP C2 at aab.sportsontheweb[.]net. Microsoft reported the cluster and npm removed the packages and accounts.
On May 28, 2026, a single npm maintainer operating under the newly created alias "vpmdhaj" (registration email a39155771@gmail.com) published 14 malicious packages within an approximately four-hour window. The packages typosquat the OpenSearch, ElasticSearch, DevOps, and environment/config library namespaces (e.g. opensearch-setup, opensearch-setup-tool, opensearch-config-utility, elastic-opensearch-helper, env-config-manager) and combine both unscoped lookalikes and packages under the actor's own @vpmdhaj scope. To appear legitimate the packages spoofed the repository URL github.com/opensearch-project/opensearch-js and carried grossly inflated version numbers (e.g. 1.0.9108, 2.1.9201) to win npm dist-tag resolution and impersonate maturity. Microsoft Threat Intelligence tracked the cluster as a 'Mini Shai-Hulud' variant and reported it to npm, which removed the packages and suspended the maintainer accounts.
Execution is install-time and requires no application code to call require(): the packages declare npm lifecycle hooks (preinstall / install / postinstall) that run automatically during `npm install`. Two stager generations were observed. Gen-1 runs node -> preinstall.js / index.js, which beacons over HTTP to the C2 at hxxp://aab.sportsontheweb[.]net/x.php (carrying the custom header 'X-Supply: 1'), downloads payload.bin, and re-launches itself as a detached background process marked with the environment variable __DAEMONIZED=1 to survive the parent npm process exit. Gen-2 runs node -> setup.mjs, which downloads a legitimate Bun runtime (from GitHub releases) and uses it to execute a bundled, Bun-compiled second-stage credential harvester (~195 KB; observed as opensearch_init.js / ai_init.js, with the compressed payload shipped as payload.gz). Using a real, signed Bun binary to interpret the obfuscated stage-2 lets the actor blend with normal developer tooling and evade signature-based JS scanning.
The second stage is a cloud and CI/CD credential harvester. Against AWS it queries the EC2 Instance Metadata Service v2 (169.254.169.254) and the ECS task metadata endpoint (169.254.170.2), reads AWS credential environment variables, calls STS GetCallerIdentity and AssumeRole to validate and pivot on stolen roles, and enumerates Secrets Manager (ListSecrets / GetSecretValue) across 16 or more AWS regions. It reads HashiCorp Vault tokens from the VAULT_TOKEN and VAULT_AUTH_TOKEN environment variables, validates npm tokens through the registry /-/whoami endpoint and enumerates publish access via /-/npm/v1/tokens (enabling downstream supply-chain self-propagation by republishing into packages the victim maintains), and collects GitHub Actions context including GITHUB_REPOSITORY and RUNNER_OS. Harvested secrets are exfiltrated over the same HTTP C2 channel.
Impact is highest in CI/CD runners and developer/build hosts that hold ambient cloud credentials and long-lived publish tokens. Any environment that installed an affected package should treat all reachable AWS, Vault, npm, and GitHub Actions secrets as compromised and rotate them. Microsoft Defender Antivirus detects the components as Trojan:JS/ShaiWorm, Trojan:JS/ObfusNpmJs, and Backdoor:JS/SupplyChain, and Microsoft published Defender XDR advanced hunting queries for npm lifecycle script execution, the payload.bin artifact, detached __DAEMONIZED=1 processes, Bun runtime downloads, C2 beacons to the attacker domain, and AWS IMDS/ECS metadata access. This cluster is distinct from the contemporaneous TeamPCP 'Mini Shai-Hulud' worm that hit TanStack/Mistral/UiPath; it shares the family label and Bun-stager tradecraft but uses a separate actor alias, package set, and C2 infrastructure.
MITRE ATT&CK techniques used in TL-2026-0623
Defense Evasion
T1027 Obfuscated Files or Information; T1027.004 Obfuscated Files or Information: Compile After Delivery; T1036 Masquerading
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 Malicious Link
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery
Initial Access
T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
Credential Access
T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.005 Unsecured Credentials: Cloud Instance Metadata API
Persistence
T1543 Create or Modify System Process
Resource Development
T1585 Establish Accounts; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware
Affected products and versions in vpmdhaj npm Supply Chain Attack
- npm (actor: vpmdhaj) — Malicious typosquat packages (OpenSearch/ElasticSearch/DevOps/env-config)
Vulnerable versions: @vpmdhaj/elastic-helper@1.0.7269; @vpmdhaj/devops-tools@1.0.7267; @vpmdhaj/opensearch-setup@1.0.7267; @vpmdhaj/search-setup@1.0.7268; opensearch-security-scanner@1.0.10; opensearch-setup@1.0.9103; opensearch-setup-tool@1.0.9108; opensearch-config-utility@1.0.9106; search-engine-setup@1.0.9108; search-cluster-setup@1.0.9104
Fixed in: Removed from npm registry; maintainer accounts suspended (2026-05-28) - OpenSearch Project (spoofed/impersonated) — @opensearch-project/opensearch-js (legitimate target of typosquatting; spoofed repo URL github.com/opensearch-project/opensearch-js)
Vulnerable versions: N/A — legitimate package impersonated, not itself compromised in this cluster - Affected consumers — CI/CD runners, developer build hosts, and cloud workloads that ran `npm install` of an affected package
Vulnerable versions: Any environment installing affected versions 2026-05-28
Fixed in: After package removal + credential rotation
Remediation for vpmdhaj npm Supply Chain Attack
Patches
- No vendor patch — npm removed the 14 malicious packages and suspended the vpmdhaj maintainer accounts after Microsoft's report. Remediation is removal of installed copies and credential rotation.
Immediate actions
- Audit npm install logs, CI build logs, and lockfiles for any of the 14 affected packages (see affected list); remove node_modules and reinstall from a clean, verified source.
- Treat all credentials reachable from any affected build/developer environment as compromised: rotate AWS access keys, force-expire STS sessions, and rotate IAM role trust where AssumeRole may have been abused.
- Rotate HashiCorp Vault tokens (VAULT_TOKEN, VAULT_AUTH_TOKEN), npm publish tokens, and GitHub Actions secrets exposed to affected runners.
- Block the C2 domain aab.sportsontheweb[.]net (and apex sportsontheweb[.]net) and IPs 185.176.43.98 / 185.176.40.84 at egress/DNS.
- Hunt for detached node processes carrying __DAEMONIZED=1 and for HTTP requests with header 'X-Supply: 1'.
Workarounds
- Globally disable npm lifecycle scripts in automation (ignore-scripts).
- Isolate CI runners as ephemeral, credential-minimized environments.
- Quarantine and re-pull any project that resolved an affected package version.
Longer-term hardening
- Run CI installs with `npm install --ignore-scripts` (or `npm config set ignore-scripts true`) and require explicit review for packages needing lifecycle scripts.
- Enforce IMDSv2 with hop limit 1 and disable IMDS where unused; apply least-privilege ECS task roles and scope Secrets Manager access.
- Apply strict egress filtering on build runners so only approved registries/endpoints are reachable.
- Pin dependencies via lockfile + integrity hashes and use a private/proxy registry with a scoped allowlist.
- Deploy continuous typosquat and malicious-package monitoring (e.g., Socket, StepSecurity) across the dependency tree.
Weaknesses (CWE) in vpmdhaj npm Supply Chain Attack
Timeline of vpmdhaj npm Supply Chain Attack
- Microsoft publishes the blog 'Typosquatted npm packages used to steal cloud and CI/CD secrets' with full IOCs, attack-chain analysis, Defender AV signatures (Trojan:JS/ShaiWorm, Trojan:JS/ObfusNpmJs, Backdoor:JS/SupplyChain), and Defender XDR advanced hunting queries.
- npm removes the 14 malicious packages and suspends the vpmdhaj maintainer accounts.
- Microsoft reports the package cluster and maintainer accounts to npm.
- Microsoft Threat Intelligence detects the malicious cluster and identifies the install-time Bun-compiled credential harvester (Gen-1 preinstall.js/index.js HTTP-C2 stager and Gen-2 setup.mjs Bun-runtime loader).
- Actor alias 'vpmdhaj' (email a39155771@gmail.com) publishes 14 typosquatted OpenSearch/ElasticSearch/DevOps/env-config npm packages within an approximately four-hour window, using inflated version numbers and the spoofed repo URL github.com/opensearch-project/opensearch-js.
- As of 2026-05-29, the 14 vpmdhaj typosquat packages were removed from npm and the maintainer accounts suspended per Microsoft, so this specific cluster is contained. It stays a live concern: stolen AWS/Vault/npm/GitHub creds persist until rotated, the C2 (sportsontheweb[.]net) shows no takedown, and the broader Mini Shai-Hulud family is actively reusing this tradecraft.
- Threadlinqs Intelligence ingests the campaign, verifies it as a distinct cluster from the TeamPCP TanStack 'Mini Shai-Hulud' worm, and publishes full MITRE mapping, IOCs, and detection coverage.
Sources cited for vpmdhaj npm Supply Chain Attack
- Typosquatted npm packages used to steal cloud and CI/CD secrets
- Typosquatted npm Packages Execute Stealthy Credential Theft Operation
- A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit npm Packages
- Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
- GMS-2026-374: @opensearch-project/opensearch malware after npm account takeover
- The npm Threat Landscape: Attack Surface and Mitigations
Detection coverage for TL-2026-0623
As of 2026-05-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0623 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.