# vpmdhaj npm Supply Chain Attack — 14 OpenSearch/ElasticSearch Typosquats Steal AWS/Vault/CI-CD Secrets via Bun-Compiled Stager (Mini Shai-Hulud)

> A single actor under the new npm alias "vpmdhaj" published 14 typosquatted OpenSearch/ElasticSearch/DevOps packages on 2026-05-28 whose npm install-time lifecycle hooks run a ~195 KB Bun-compiled credential harvester. The stager steals AWS credentials (IMDSv2, ECS task roles, Secrets Manager across 16+ regions), HashiCorp Vault tokens, npm publish tokens, and GitHub Actions context, exfiltrating over HTTP C2 at aab.sportsontheweb[.]net. Microsoft reported the cluster and npm removed the packages and accounts.

- **Published:** 2026-05-29T00:00:00Z
- **Last reviewed:** 2026-05-29T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0623
- **ID:** TL-2026-0623
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 42 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On May 28, 2026, a single npm maintainer operating under the newly created alias "vpmdhaj" (registration email a39155771@gmail.com) published 14 malicious packages within an approximately four-hour window. The packages typosquat the OpenSearch, ElasticSearch, DevOps, and environment/config library namespaces (e.g. opensearch-setup, opensearch-setup-tool, opensearch-config-utility, elastic-opensearch-helper, env-config-manager) and combine both unscoped lookalikes and packages under the actor's own @vpmdhaj scope. To appear legitimate the packages spoofed the repository URL github.com/opensearch-project/opensearch-js and carried grossly inflated version numbers (e.g. 1.0.9108, 2.1.9201) to win npm dist-tag resolution and impersonate maturity. Microsoft Threat Intelligence tracked the cluster as a 'Mini Shai-Hulud' variant and reported it to npm, which removed the packages and suspended the maintainer accounts.

Execution is install-time and requires no application code to call require(): the packages declare npm lifecycle hooks (preinstall / install / postinstall) that run automatically during `npm install`. Two stager generations were observed. Gen-1 runs node -> preinstall.js / index.js, which beacons over HTTP to the C2 at hxxp://aab.sportsontheweb[.]net/x.php (carrying the custom header 'X-Supply: 1'), downloads payload.bin, and re-launches itself as a detached background process marked with the environment variable __DAEMONIZED=1 to survive the parent npm process exit. Gen-2 runs node -> setup.mjs, which downloads a legitimate Bun runtime (from GitHub releases) and uses it to execute a bundled, Bun-compiled second-stage credential harvester (~195 KB; observed as opensearch_init.js / ai_init.js, with the compressed payload shipped as payload.gz). Using a real, signed Bun binary to interpret the obfuscated stage-2 lets the actor blend with normal developer tooling and evade signature-based JS scanning.

The second stage is a cloud and CI/CD credential harvester. Against AWS it queries the EC2 Instance Metadata Service v2 (169.254.169.254) and the ECS task metadata endpoint (169.254.170.2), reads AWS credential environment variables, calls STS GetCallerIdentity and AssumeRole to validate and pivot on stolen roles, and enumerates Secrets Manager (ListSecrets / GetSecretValue) across 16 or more AWS regions. It reads HashiCorp Vault tokens from the VAULT_TOKEN and VAULT_AUTH_TOKEN environment variables, validates npm tokens through the registry /-/whoami endpoint and enumerates publish access via /-/npm/v1/tokens (enabling downstream supply-chain self-propagation by republishing into packages the victim maintains), and collects GitHub Actions context including GITHUB_REPOSITORY and RUNNER_OS. Harvested secrets are exfiltrated over the same HTTP C2 channel.

Impact is highest in CI/CD runners and developer/build hosts that hold ambient cloud credentials and long-lived publish tokens. Any environment that installed an affected package should treat all reachable AWS, Vault, npm, and GitHub Actions secrets as compromised and rotate them. Microsoft Defender Antivirus detects the components as Trojan:JS/ShaiWorm, Trojan:JS/ObfusNpmJs, and Backdoor:JS/SupplyChain, and Microsoft published Defender XDR advanced hunting queries for npm lifecycle script execution, the payload.bin artifact, detached __DAEMONIZED=1 processes, Bun runtime downloads, C2 beacons to the attacker domain, and AWS IMDS/ECS metadata access. This cluster is distinct from the contemporaneous TeamPCP 'Mini Shai-Hulud' worm that hit TanStack/Mistral/UiPath; it shares the family label and Bun-stager tradecraft but uses a separate actor alias, package set, and C2 infrastructure.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1587.001 Develop Capabilities: Malware
- T1608.001 Stage Capabilities: Upload Malware
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1204.001 Malicious Link
- T1543 Create or Modify System Process
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1027.004 Obfuscated Files or Information: Compile After Delivery
- T1552.005 Unsecured Credentials: Cloud Instance Metadata API
- T1552.001 Unsecured Credentials: Credentials In Files
- T1528 Steal Application Access Token
- T1580 Cloud Infrastructure Discovery
- T1526 Cloud Service Discovery
- T1082 System Information Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [Typosquatted npm packages used to steal cloud and CI/CD secrets](https://www.microsoft.com/en-us/security/blog/2026/05/28/typosquatted-npm-packages-used-steal-cloud-ci-cd-secrets/)
- [Typosquatted npm Packages Execute Stealthy Credential Theft Operation](https://hivepro.com/threat-advisory/typosquatted-npm-packages-execute-stealthy-credential-theft-operation/)
- [A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit npm Packages](https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared)
- [Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages](https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html)
- [GMS-2026-374: @opensearch-project/opensearch malware after npm account takeover](https://advisories.gitlab.com/npm/@opensearch-project/opensearch/GMS-2026-374/)
- [The npm Threat Landscape: Attack Surface and Mitigations](https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0623
