VHX Harvester Uses npm Typosquats to Target Vast.ai GPU Instances

Summary
CloudSek analyzes VHX Harvester, a live operation targeting Vast.ai GPU instances through npm typosquats. It reports 25 deployed bridge agents and one confirmed root shell; the operator remains active, but no miners have been planted.
Key points
- CloudSek linked 85 packages published under the @prime0 npm scope to infrastructure hosting the VHX Harvester panel.
- The panel used Vast.ai’s public API to enumerate 297 host IPs and scanned 13,368 service endpoints, extracting metadata from 416 services.
- The operator deployed 25 bridge agents on rented GPU instances and obtained one confirmed root shell on a victim’s Jupyter notebook.
- The agent’s documented attack chain includes service scanning, credential harvesting, stored XSS targeting Caddy auth portals, and scanning Docker bridge networks from containers rented on the same host.
- Seventeen panel API endpoints reportedly lacked authentication; one exposed the agent source code, which contained default credentials granting full panel access.
- As of September 25, 2026, the operation remained active and was still attempting to rent instances. CloudSek reported that no cryptocurrency miners had been planted.
- CloudSek recommends Vast.ai defenders review Caddy auth proxy configuration, watch for containers scanning 172.17.0.0/16, and treat downloads from 69.48.229.140 as hostile.
Article Details
- Attack Vectors
- The companion report documented 85 npm packages under the @prime0 scope that beaconed to the operator's infrastructure when installed.
- The VHX Harvester panel enumerated GPU hosts through the vast.ai public API and scanned service endpoints on those hosts.
- The panel exfiltrated metadata from 416 services and deployed 25 bridge agents onto rented GPU instances. Its described bridge-agent model rents a container on the target's physical host to scan the Docker bridge network.
- The agent source describes credential harvesting, stored XSS injection into Caddy auth proxy error logs to steal session tokens, access to unprotected Jupyter notebooks, and cryptocurrency-miner deployment. The report confirms one root shell on a victim's Jupyter notebook but says no miners had been planted.
- Seventeen panel API endpoints required no authentication. The /agent/code.tar.gz endpoint exposed the complete C2 agent source, including hardcoded default credentials that granted full panel access.
- Defensive Notes
- Audit vast.ai Caddy auth proxy configurations for the bypass associated with the reported root-shell access.
- Monitor rented containers for scans of 172.17.0.0/16 on the Docker bridge.
- Treat rented instances that download code from 69.48.229.140 as hostile.
- Report the operator's infrastructure to its hosting provider.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 69[.]48[.]229[.]140 | Operator infrastructure contacted by the npm packages on installation; it also hosted the VHX Harvester panel. |
MITRE ATT&CK
T1190 · Exploit Public-Facing ApplicationThe report attributes a confirmed root shell on a victim's Jupyter notebook to a Caddy auth proxy bypass.T1595 · Active ScanningThe panel enumerated 297 host IPs from the vast.ai public API and scanned 13,368 service endpoints.T1608.001 · Upload MalwareThe operator published 85 npm packages under the @prime0 scope that beaconed to its infrastructure on installation.
Products
Caddyclassify and fingerprint services, harvest credentials and metadata, inject stored XSS into vast.ai's Caddy auth portals to steal session tokens, rent cheap containers on the same physical host as the target toDockerto steal session tokens, rent cheap containers on the same physical host as the target to scan the Docker bridge network, access unprotected Jupyter notebooks for root shells, and deploy cryptocurrency minersJupyterdeployed 25 bridge agents onto rented GPU instances, and achieved one confirmed root shell on a victim's Jupyter notebook. No cryptocurrency miners have been planted. The operator is still active: the panel's activitynpmThe companion report GTI-TOPHIT documented 85 npm packages published under the @prime0 scope, all of which beaconed to 69.48.229.140:8080 on installation. That infrastructure has a second service on port 80. It is avast.aioffensive panel called VHX Harvester, version 0.1.0, and it runs a live operation against the vast.ai GPU rental marketplace. As of 25 September 2026, the panel has enumerated 297 host IPs from the vast.ai