CloudSEK is out with a two-part investigation — TOPHIT — uncovering a threat operation that connects a large-scale npm supply-chain campaign with an emerging GPU cryptojacking framework targeting the vast.ai marketplace.
In Part 1, CloudSEK researchers found that a single npm account, @prime0, published 85 typosquatted packages in just over three minutes, targeting 29 of the ecosystem’s most widely downloaded libraries, including chalk, semver, debug, minimatch and ajv. The packages were designed to beacon system information to a command-and-control server and, when loaded, could poll the server every 30 seconds for commands to execute on the infected machine.
The researchers found that the same server hosting the npm command infrastructure was also running VHX Harvester, a purpose-built offensive framework targeting the vast.ai GPU rental marketplace, which CloudSEK investigates in Part 2. The evidence currently establishes shared infrastructure and an assessed common operator, rather than proving that the npm campaign was directly feeding victims into the GPU operation.
Key findings from the investigation
- 85 malicious npm packages were published by one account within approximately 3 minutes and 13 seconds, indicating automated mass deployment rather than manual publishing.
- The packages imitated 29 extremely popular npm libraries, with every target library recording at least 181 million weekly downloads.
- The malware could collect details including the hostname, username, operating system, working directory, IP addresses and Node.js version, and could establish a remote command channel when the package was loaded.
- The same infrastructure exposed VHX Harvester, a GPU-focused offensive platform actively targeting vast.ai.
- By September 25, the framework had enumerated 297 GPU host IPs, scanned 13,368 service endpoints, harvested metadata from 416 services, deployed 25 bridge agents and achieved one confirmed root shell on a victim Jupyter notebook.
- CloudSEK found that 17 API endpoints on the attacker’s own panel required no authentication, exposing the framework’s API documentation and even its complete agent source code with hardcoded credentials.
- Researchers also found 208 exfiltrated files, including 98 environment-variable dumps containing API keys, database credentials and cloud-service tokens from victim GPU instances.
- The framework outlines an eight-stage attack chain, moving from GPU-host discovery and scanning to credential harvesting, lateral movement through Docker networks, Jupyter access and ultimately the intended deployment of cryptocurrency miners. At the time of CloudSEK’s investigation, no miners had yet been planted, indicating the operation was still developing.
One particularly interesting technique is the use of legitimately rented GPU containers as “bridge agents”. The operator rents a low-cost container on the same physical host as a target and then scans the internal Docker bridge network, potentially reaching services that are not exposed directly to the internet.
Here’s both parts of CloudSEK’s investigation below:
Part 1: A One-Operator npm Typosquat Flood, Co-hosted with a GPU-Cryptojacking C2
Part 2: Renting the Attack Surface: A GPU Cryptojacking Framework Targeting vast.ai, Exposed by Its Own Misconfiguration
Related
This entry was posted on September 29, 2026 at 8:44 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
CloudSEK Traces 85 npm Typosquats to Infrastructure Hosting a GPU Attack Framework Targeting vast.ai
CloudSEK is out with a two-part investigation — TOPHIT — uncovering a threat operation that connects a large-scale npm supply-chain campaign with an emerging GPU cryptojacking framework targeting the vast.ai marketplace.
In Part 1, CloudSEK researchers found that a single npm account, @prime0, published 85 typosquatted packages in just over three minutes, targeting 29 of the ecosystem’s most widely downloaded libraries, including chalk, semver, debug, minimatch and ajv. The packages were designed to beacon system information to a command-and-control server and, when loaded, could poll the server every 30 seconds for commands to execute on the infected machine.
The researchers found that the same server hosting the npm command infrastructure was also running VHX Harvester, a purpose-built offensive framework targeting the vast.ai GPU rental marketplace, which CloudSEK investigates in Part 2. The evidence currently establishes shared infrastructure and an assessed common operator, rather than proving that the npm campaign was directly feeding victims into the GPU operation.
Key findings from the investigation
One particularly interesting technique is the use of legitimately rented GPU containers as “bridge agents”. The operator rents a low-cost container on the same physical host as a target and then scans the internal Docker bridge network, potentially reaching services that are not exposed directly to the internet.
Here’s both parts of CloudSEK’s investigation below:
Part 1: A One-Operator npm Typosquat Flood, Co-hosted with a GPU-Cryptojacking C2
Part 2: Renting the Attack Surface: A GPU Cryptojacking Framework Targeting vast.ai, Exposed by Its Own Misconfiguration
Share this:
Like this:
Related
This entry was posted on September 29, 2026 at 8:44 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.