www.microsoft.com 5/29/2026, 4:29:40 AM · external

Microsoft warns of npm chain attack stealing AWS, Vault data

Microsoft warns of npm chain attack stealing AWS, Vault data
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT identified a supply chain attack targeting the npm package ecosystem on May 28, 2026, involving a threat actor using the alias vpmdhaj. The actor published 14 malicious packages that typosquatted well-known libraries and, once installed, harvested AWS credentials, HashiCorp Vault tokens, and CI/CD pipeline secrets.

The packages utilized automatic payload execution through npm hooks, employing two variants of malicious payloads to steal sensitive credentials and enable lateral movement across cloud environments. Key tactics included lookalike naming, spoofed metadata, and inflated version numbers to trick users into installing the packages. Microsoft recommends several mitigation strategies, including disabling script execution during installations and rotating potentially compromised credentials.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline