A large-scale npm supply-chain campaign has been linked to an emerging cryptojacking operation targeting rented GPUs, after researchers found both operations using the same command-and-control infrastructure.
Cybersecurity researchers at CloudSEK said a single npm account, @prime0, published 85 typosquatted packages targeting 29 widely used JavaScript libraries in about three minutes and 13 seconds. The packages mimicked libraries including chalk, semver, debug, minimatch and ajv, each of which has at least 181 million weekly downloads.
The packages were designed to collect information from infected systems, including hostnames, usernames, operating systems, working directories, IP addresses and Node.js versions. Once loaded, they could also poll a command-and-control server every 30 seconds for instructions to execute on the compromised machine.
CloudSEK’s investigation, dubbed TOPHIT, found that the server supporting the npm operation was also hosting VHX Harvester, an offensive framework targeting the vast.ai GPU rental marketplace.
The researchers said the evidence points to shared infrastructure and a common operator, but does not establish that victims of the npm campaign were subsequently used in the GPU operation.
By 25th September, VHX Harvester had identified 297 GPU host IP addresses, scanned 13,368 service endpoints and harvested metadata from 416 services, according to CloudSEK. The framework had also deployed 25 bridge agents and obtained one confirmed root shell on a victim’s Jupyter notebook.
The operation was particularly notable for its use of rented GPU containers as “bridge agents”. An attacker can rent a low-cost container on the same physical host as a target and use it to scan the internal Docker bridge network, potentially reaching services that are not directly exposed to the internet.
CloudSEK said the framework’s intended attack chain runs from GPU-host discovery and service scanning through credential harvesting and lateral movement across Docker networks to Jupyter access and, ultimately, the deployment of cryptocurrency miners.
At the time of the investigation, however, the researchers had found no evidence that miners had been deployed, suggesting the operation was still being developed.
The attackers also appear to have exposed parts of their own infrastructure. CloudSEK found 17 API endpoints on the operation’s control panel that did not require authentication, providing access to API documentation and the framework’s complete agent source code, including hardcoded credentials.
The researchers identified 208 exfiltrated files, including 98 environment-variable dumps containing API keys, database credentials and cloud-service tokens taken from victim GPU instances.
CloudSEK’s findings are split across two reports. The first examines the npm typosquatting campaign and its shared infrastructure with the GPU operation, while the second details the VHX Harvester framework and its targeting of vast.ai.
The investigation highlights how attacks against software supply chains can intersect with attacks on Cloud and GPU infrastructure, while also showing how exposed attacker infrastructure can provide researchers with visibility into an operation’s tools and methods.
