All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Attacker publishes 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries

2d ago· 1 min readenNews

Summary

A single npm user published 14 malicious packages over four hours, impersonating popular OpenSearch, Elasticsearch, DevOps, and environment-configuration libraries. The packages used a newly created maintainer alias (vpmdhaj) and targeted the @opensearch and @elastic ecosystems, aiming at AWS, HashiCorp Vault, GitHub Actions, and the npm registry. Each package contained an install-time stager and a 195 KB Bun-compiled second-stage credential harvester designed to steal tokens from cloud and CI/CD environments.

Key quotes

· 3 pulled
A single npm user published 14 malicious packages over a four-hour window, impersonating popular OpenSearch, Elasticsearch, DevOps, and environment-configuration libraries.
The packages used a newly created maintainer alias, vpmdhaj (a39155771@gmail[.]com), and targeted the @opensearch and @elastic ecosystems.
Each package contained the same install-time stager and a Bun-compiled second-stage credential harvester of 195 KB for cloud and CI/CD environments.
Snippet from the RSS feed
A single npm user published 14 malicious packages impersonating OpenSearch/Elasticsearch libraries to steal AWS, Vault, and CI/CD secrets.

You might also wanna read