vpmdhaj OpenSearch / ElasticSearch / DevOps typosquat burst (14 npm packages, Bun stager → cloud + CI/CD secret theft)
Microsoft Threat Intelligence flagged 14 typosquat npm packages published on 2026-05-28 by a single new maintainer alias vpmdhaj (a39155771@gmail.com) in a ~4-hour window. Install-time stager pulls a ~195KB Bun-compiled credential harvester from aab.sportsontheweb[.]net/x.php (X-Supply: 1 header) and exfiltrates AWS, HashiCorp Vault, GitHub Actions and npm publish tokens.
Versions named here: 1.0.7265, 1.0.9102, 1.0.9103, 1.0.9104