Skip to content

Typosquatted npm Packages Steal Cloud and CI/CD Secrets

Gbhackers Mayura Kathir May 29, 2026

A coordinated npm supply chain attack has been uncovered targeting developers working with OpenSearch, ElasticSearch, and DevOps tooling, with attackers actively stealing cloud credentials and CI/CD secrets from infected systems. The malicious packages imitate legitimate libraries by using lookalike names such as opensearch-setup and elastic-opensearch-helper, while falsely linking to the official OpenSearch GitHub repository in […]

Extracted Entities