vpmdhaj is a threat actor associated with a malicious npm supply-chain campaign identified in May 2026. Operating through the npm maintainer alias vpmdhaj, the actor published multiple typosquatted packages impersonating OpenSearch-, ElasticSearch-, DevOps-, and configuration-related libraries. The campaign relied on npm lifecycle hooks to trigger code execution during package installation, enabling immediate compromise of developer workstations and CI/CD environments. The actor’s tooling deployed a Bun-compiled second-stage credential harvester designed to steal cloud and software supply-chain secrets. Observed targets included AWS credentials, HashiCorp Vault tokens, GitHub Actions context and tokens, and npm publish tokens. The malware inspected environment variables, checked for GitHub Actions execution contexts, queried cloud metadata services, and enumerated AWS resources across numerous regions, including identity and secrets-related services. Theft of npm publish tokens created a credible risk of downstream compromise of legitimate packages and maintainer accounts. Two loader variants were observed. An earlier variant retrieved its payload from external command-and-control infrastructure, while a later variant reduced overt network activity by downloading the legitimate Bun runtime and executing a bundled malicious script locally. The campaign also demonstrated persistence behavior by relaunching the payload on subsequent module loads. Overall, vpmdhaj exhibited capabilities spanning initial access through software supply-chain abuse, credential theft, reconnaissance of cloud and CI/CD environments, persistence, and exfiltration. The activity is consistent with a financially motivated actor seeking reusable credentials and tokens that could enable broader follow-on compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.