All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Microsoft detects 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries

By

Jessica Lyons

1d ago· 3 min readenNews

Summary

A threat actor using the alias vpmdhaj published 14 malicious npm packages within four hours, impersonating legitimate OpenSearch, Elasticsearch, DevOps, and environment-configuration libraries. The packages were designed to steal cloud credentials and CI/CD pipeline secrets in a supply chain attack targeting developer tools. Microsoft detected and reported the malicious packages, which were published from a newly created maintainer account.

Key quotes

· 3 pulled
A single npm user on Thursday published 14 malicious packages within a four-hour window, all mimicking popular OpenSearch, Elasticsearch, DevOps, and environment-configuration libraries, according to Microsoft.
It's the latest in a seemingly never-ending string of supply chain attacks targeting developer tools, and stealing cloud credentials and CI/CD pipeline secrets in its wake.
Using a newly created maintainer alias, vpmdhaj (a39155771@gmail[.]com), the threat actor published 14 packages impersonating legitimate libraries from the @opensearch and @elastic ecosystems
Snippet from the RSS feed
And then Microsoft busted them all

You might also wanna read