npm typosquat flood leads to a GPU cloud hacking panel

Published

In a little over three minutes on September 15, a single npm account called prime0 published 85 packages, each a one or two character misspelling of a popular library such as chalk, semver, debug, minimatch or ajv. Every one carried the same remote command code. The server those packages reported to turned out to be running a second, stranger operation on another port: a live panel for breaking into GPU machines rented out on the vast.ai marketplace. Vikas Kundu of CloudSEK laid out both halves in a two-part series, TOPHIT Part 1 and TOPHIT Part 2.

Typos built for the search box, not the terminal

The names look like classic typosquats, but CloudSEK says they were generated by an algorithm and built for a different route. All 85 sit under the @prime0 scope, and none has an unscoped twin, so a developer who mistypes "npm install fhalk" just gets a not-found error. The same typo in npm's search or an editor's package autocomplete, however, would put @prime0/fhalk at the top of the results, because the search ranks a scoped package first when no unscoped package carries the name.

Installing one sends a fingerprint of the machine to 69[.]48[.]229[.]140 on port 8080. Loading it in a program starts an agent that asks that server for a shell command every 30 seconds, runs it and returns the output. Only three of the packages appeared in public malicious package advisories, and the scope has since been removed from the registry. CloudSEK is careful to say nothing in its analysis shows a successful compromise, or that any developer actually found the packages through search.

Renting a room next door to the victim

Port 80 on the same host served a panel called VHX Harvester, version 0.1.0. As of September 25, CloudSEK says, it had enumerated 297 host IPs from vast.ai's public API, scanned 13,368 service endpoints, pulled metadata from 416 services, deployed 25 bridge agents onto rented GPU instances and obtained one confirmed root shell, on a victim's unprotected Jupyter notebook.

The panel was also badly misconfigured. Seventeen of its API endpoints needed no login, including one serving the full agent source code with hardcoded default credentials. That source spells out an eight-phase plan: enumerate GPU hosts, scan and fingerprint their services, harvest credentials, inject stored cross-site scripting into vast.ai's Caddy authentication portals to steal session tokens, rent cheap containers on the same physical host as a target to scan its Docker bridge network, take over exposed Jupyter notebooks, and finally deploy cryptocurrency miners. No miners have been planted yet, and CloudSEK describes the operation as still in development.

GPU cryptojacking is not new, but CloudSEK says three things here have no documented precedent: the co-tenant bridge agents, the XSS injection through the Caddy proxy's error logs, and npm typosquats used as a discovery route for GPU infrastructure. It assesses the two operations share an operator, but stresses the established link is shared infrastructure, not one campaign feeding the other. It follows CloudSEK's earlier npm investigations, TXTBOOK and GHAPPIER.

Block the host, search lockfiles for @prime0

CloudSEK recommends blocking 69[.]48[.]229[.]140 at egress and searching dependency manifests and lockfiles for any @prime0 reference. A machine that only installed one of the packages should be treated as having disclosed its host details; a machine or build runner where a program loaded one should be treated as having run an attacker-controlled command channel for as long as that program ran. vast.ai users should audit their Caddy auth proxy configuration, watch for containers scanning 172[.]17[.]0[.]0/16 on the Docker bridge, and treat any rented instance that downloads code from that IP as hostile.

The quieter lesson is about where developers actually find packages. Guarding the install command is not enough when the suggestion list is doing the choosing.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions