CloudSEK reported that an exposed VHX Harvester v0.1.0 FastAPI panel at 69.48.229.140 was being used to prepare a cryptojacking operation against hosts on the vast.ai GPU-rental marketplace. The panel allegedly enumerated GPU hosts, scanned exposed services, harvested metadata and environment variables, deployed bridge agents into co-resident containers to probe Docker bridge networks, and obtained one root shell on a Jupyter Notebook instance. Its source code also described planned credential harvesting, stored-XSS attacks against Caddy authentication portals, Jupyter compromise, and cryptocurrency mining; no miner deployment had been observed. As of September 25, CloudSEK reported 297 discovered hosts, 13,368 scanned endpoints, 416 findings, and 25 bridge agents.
The infrastructure was linked to 85 malicious @prime0 npm packages published within minutes and impersonating 29 popular libraries through generated misspellings. Package installation reportedly beaconed host information to 69.48.229.140:8080, while at least one package could poll the server every 30 seconds for shell commands. CloudSEK assessed that scoped package names were intended to influence npm search and autocomplete rather than capture ordinary unscoped installation typos, and cautioned that shared C2 infrastructure does not prove the npm packages enabled the GPU operation. The @prime0 scope was removed; organizations should investigate dependency manifests and lockfiles for @prime0 references, review potential execution on affected developer or build hosts, and validate reported indicators before blocking or SIEM ingestion.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
By this date, the alleged VHX Harvester operation had enumerated 297 vast.ai GPU hosts, scanned 13,368 service endpoints, and collected metadata from 416 services. It had deployed 25 co-resident bridge agents and reportedly obtained one root shell on an exposed Jupyter Notebook instance, but had not deployed a cryptocurrency miner.
The npm account prime0 published 85 packages under the @prime0 scope in approximately three minutes, impersonating 29 popular libraries. The packages contained remote-command code that fingerprinted hosts during installation and could poll 69.48.229.140:8080 for shell commands when imported.
CloudSEK published its second TOPHIT analysis describing an exposed VHX Harvester v0.1.0 panel at 69.48.229.140. The report said 17 API endpoints lacked authentication and that an exposed agent archive leaked C2 source code and hardcoded panel credentials.
The @prime0 scope was subsequently removed from the npm registry after the malicious-package activity was identified. The reporting did not establish that any developer installed the packages or was successfully compromised.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cloudsek.com
Open sourcecloudsek.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.