COMPAMIR
High-Purity Fact Pipeline
© 2026 COMPAMIR | Verified Intelligence
High-Purity Fact Pipeline
Unknown threat actor (alias: vpmdhaj)
Global
May 30, 2026
Verified: May 30, 2026
"A threat actor published 14 malicious npm packages mimicking popular developer tools. The packages target AWS, HashiCorp Vault, GitHub Actions, and npm credentials. The attack uses typosquatting and metadata spoofing to deceive developers."
Author: Mark Dowd, John McDonald, and Justin Schuh
This book provides a deep dive into the mechanics of software vulnerabilities and the supply chain risks inherent in modern development environments, which is essential for understanding how malicious packages exploit CI/CD pipelines.
As an Amazon Associate, COMPAMIR earns from qualifying purchases.