Security

Typosquatted npm Packages Steal Cloud and CI/CD Secrets

3 min read

Summary

Microsoft has uncovered an active npm supply chain attack in which 14 typosquatted packages stole AWS credentials, HashiCorp Vault tokens, GitHub Actions data, and npm publish tokens during installation. The campaign matters because it targets developer and build environments, creating risk of cloud lateral movement, CI/CD compromise, and downstream software supply chain attacks.

Need help with Security?Talk to an Expert

Introduction

Microsoft has identified a serious npm supply chain campaign that targeted developers and build systems through typosquatted packages. Although the malicious packages have been removed, the techniques used in this attack show how quickly cloud credentials and CI/CD secrets can be exposed during a routine npm install.

For IT and security teams, this is a reminder that package managers remain a high-value attack path, especially in environments with access to AWS, Vault, GitHub Actions, and npm publishing tokens.

What’s new

Microsoft Defender Security Research reported that a single threat actor published 14 malicious npm packages within a four-hour period. These packages impersonated OpenSearch, ElasticSearch, DevOps, and environment configuration libraries.

Key findings include:

  • Typosquatted package names designed to look like legitimate OpenSearch and Elastic-related packages
  • Spoofed repository metadata pointing to the real OpenSearch project to build trust
  • Automatic execution during install via npm preinstall, install, or postinstall hooks
  • Two-stage malware delivery, including a newer variant that abuses the legitimate Bun runtime as a stealthier loader
  • Credential theft targeting:
    • AWS credentials from environment variables, IMDSv2, and ECS task metadata
    • AWS Secrets Manager across more than 16 regions
    • HashiCorp Vault tokens
    • GitHub Actions environment context
    • npm publish tokens for follow-on supply chain attacks

Why this matters for administrators

This attack goes beyond a single compromised workstation. If a malicious package runs inside a CI/CD pipeline or cloud-connected development environment, attackers may gain access to:

  • Cloud accounts and temporary AWS sessions
  • Secrets stored in AWS Secrets Manager
  • Build and deployment pipelines
  • npm maintainer tokens that could be used to publish malicious updates downstream

That creates a much larger blast radius than a typical developer malware incident. A compromised build agent or runner could become the starting point for cloud lateral movement or software supply chain compromise.

Administrators should review development and pipeline environments for exposure and strengthen package controls.

  • Audit npm dependencies for recently installed lookalike packages related to OpenSearch or ElasticSearch
  • Review build logs and proxy logs for suspicious install-time activity, including unusual lifecycle hook execution
  • Hunt for indicators such as requests with the X-Supply: 1 header or unexpected Bun downloads during package installation
  • Rotate exposed secrets immediately, including AWS credentials, Vault tokens, GitHub Actions secrets, and npm publish tokens
  • Restrict package installation sources and consider allowlists for approved registries and packages
  • Enable Defender XDR and advanced hunting to detect suspicious package execution and credential access behavior

Bottom line

This campaign highlights how a simple typo in an npm package name can lead to credential theft across cloud and CI/CD environments. Security teams should treat developer endpoints and build systems as critical assets and apply the same monitoring, secret hygiene, and supply chain protections used elsewhere in the enterprise.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

npmsupply chain securityCI/CDAWS credentialsMicrosoft Defender

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.