Overview
Microsoft reported a May 2026 npm supply-chain campaign that used typosquatted package names to target developers and CI/CD environments. The campaign focused on packages that looked related to OpenSearch, ElasticSearch, DevOps, or environment-configuration tooling and was associated with cloud and pipeline credential theft.
Why it matters
A malicious npm package can execute during dependency installation before application code imports it. If that install happens on a developer workstation, CI runner, build container, or deployment image with cloud, registry, Vault, GitHub, or npm credentials available, those credentials may need incident-response handling even when the application itself never used the package at runtime.
Covered by FixVibe
FixVibe's GitHub repo scans flag package manifests and lockfiles that resolve known Microsoft-reported typosquat package versions from this campaign, with the package, version and file, citing the public research.
Remediation
Remove the typosquat package and regenerate the active npm, pnpm, or Yarn lockfile from a trusted registry state. If similar functionality is needed, verify the intended legitimate package name, maintainer, and repository before adding a replacement.
Rebuild CI images, devcontainers, Docker layers, dependency caches, and deployed artifacts that may have installed the affected package. If any affected package may have installed where secrets were available, rotate npm publish tokens, GitHub tokens, cloud credentials, HashiCorp Vault tokens, CI/CD secrets, SSH keys, and deployment credentials through the owning provider workflows.
