Attacker publishes 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries
Lightly toasted, lightly seasoned, mostly correct.
Summary
A single npm user published 14 malicious packages over four hours, impersonating popular OpenSearch, Elasticsearch, DevOps, and environment-configuration libraries. The packages used a newly created maintainer alias (vpmdhaj) and targeted the @opensearch and @elastic ecosystems, aiming at AWS, HashiCorp Vault, GitHub Actions, and the npm registry. Each package contained an install-time stager and a 195 KB Bun-compiled second-stage credential harvester designed to steal tokens from cloud and CI/CD environments.
Key quotes
· 3 pulledA single npm user published 14 malicious packages over a four-hour window, impersonating popular OpenSearch, Elasticsearch, DevOps, and environment-configuration libraries.
The packages used a newly created maintainer alias, vpmdhaj (a39155771@gmail[.]com), and targeted the @opensearch and @elastic ecosystems.
Each package contained the same install-time stager and a Bun-compiled second-stage credential harvester of 195 KB for cloud and CI/CD environments.
You might also wanna read
317 npm Packages Compromised in Mini Shai-Hulud Supply Chain Attack
A major npm supply chain attack occurred on May 19, 2026, when the npm account of maintainer "atool" was compromised. The attacker published
Major NPM Supply Chain Attack: @ctrl/tinycolor and 40+ Packages Compromised with Self-Propagating Malware
A sophisticated supply chain attack has compromised the popular @ctrl/tinycolor NPM package (with over 2 million weekly downloads) along wit
Security Alert: Malicious Nx Packages Published to npm Containing Credential-Stealing Code
Malicious versions of the Nx package and several supporting plugins were published to npm, containing code that scans file systems, collects
Major NPM Supply Chain Attack: Over 1,000 Packages Infected via Fake Bun Runtime
A major cybersecurity incident occurred where over 1,000 NPM packages and 27,000+ GitHub repositories were infected within hours via a fake
NPM supply chain attack compromises popular packages, posing widespread security risk
A significant supply chain attack on the NPM package ecosystem compromised several popular packages, potentially allowing malicious code to
Shai-Hulud: Largest npm Supply-Chain Compromise Affecting CrowdStrike and Hundreds of Packages
The Shai-Hulud malware campaign represents the largest and most dangerous npm supply-chain compromise in history, affecting hundreds of pack
