Microsoft detects malicious npm packages targeting OpenSearch, Elasticsearch
TL;DR. A single attacker published 14 malicious npm packages mimicking OpenSearch and Elasticsearch libraries, aiming to steal cloud and CI/CD credentials. - The packages installed credential-harvesting payloads designed for developer environments like AWS and GitHub Actions. - Microsoft identified the threat actor and removed the compromised libraries within four hours of publication. - Exposed credentials, including AWS IAM, HashiCorp Vault, and npm publish tokens, require immediate rotation.
- A lone attacker deployed 14 malicious npm packages impersonating popular OpenSearch and Elasticsearch libraries.
- The packages contained a credential harvester targeting cloud and CI/CD environments, specifically AWS, HashiCorp Vault, GitHub Actions, and npm registry.
- Microsoft detected the attack quickly, leading to the removal of all malicious packages and a public warning for users to rotate potentially exposed tokens.