Typosquatted npm packages used to steal cloud and CI/CD secrets
Reported 29 May 2026 by otx · Severity: medium
A supply chain attack targeting the npm ecosystem was identified involving 14 malicious packages published under the alias vpmdhaj. These packages typosquat well-known OpenSearch, ElasticSearch, and DevOps libraries, executing malicious payloads through npm lifecycle hooks during