Typosquatted npm packages steal cloud and CI/CD secrets
Microsoft has identified an active supply chain attack targeting the npm ecosystem. On 28 May 2026 a threat actor using the maintainer alias vpmdhaj published 14 malicious packages within a four-hour window. The packages typosquat well-known OpenSearch, ElasticSearch, DevOps and environment-configuration libraries, and several spoof the upstream OpenSearch project's repository URL in their package.json to appear legitimate. Once installed, they harvest AWS credentials, HashiCorp Vault tokens and CI/CD pipeline secrets from the host environment.
What this means for your organisation
The attack requires no vulnerability, only a typo or a quick copy from a tutorial. Secrets harvested from a build environment often provide direct access to cloud resources, making the distance short from an unlucky install to unauthorised access in production. Because the packages imitate credible project names, a visual check is not sufficient.
Berigo recommends
- Block installation of unapproved packages and use an internal mirror or registry.
- Review dependency files for recently introduced packages with names resembling known libraries.
- Rotate AWS keys and Vault tokens that have been available in the build environment.
- Replace static cloud keys with short-lived, role-based credentials in the build chain.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch