VHX Harvester Uses npm Typosquats to Target Vast.ai GPU Instances

· Original article ↗

Summary

CloudSek analyzes VHX Harvester, a live operation targeting Vast.ai GPU instances through npm typosquats. It reports 25 deployed bridge agents and one confirmed root shell; the operator remains active, but no miners have been planted.

Key points

  • CloudSek linked 85 packages published under the @prime0 npm scope to infrastructure hosting the VHX Harvester panel.
  • The panel used Vast.ai’s public API to enumerate 297 host IPs and scanned 13,368 service endpoints, extracting metadata from 416 services.
  • The operator deployed 25 bridge agents on rented GPU instances and obtained one confirmed root shell on a victim’s Jupyter notebook.
  • The agent’s documented attack chain includes service scanning, credential harvesting, stored XSS targeting Caddy auth portals, and scanning Docker bridge networks from containers rented on the same host.
  • Seventeen panel API endpoints reportedly lacked authentication; one exposed the agent source code, which contained default credentials granting full panel access.
  • As of September 25, 2026, the operation remained active and was still attempting to rent instances. CloudSek reported that no cryptocurrency miners had been planted.
  • CloudSek recommends Vast.ai defenders review Caddy auth proxy configuration, watch for containers scanning 172.17.0.0/16, and treat downloads from 69.48.229.140 as hostile.

Article Details

Attack Vectors
  • The companion report documented 85 npm packages under the @prime0 scope that beaconed to the operator's infrastructure when installed.
  • The VHX Harvester panel enumerated GPU hosts through the vast.ai public API and scanned service endpoints on those hosts.
  • The panel exfiltrated metadata from 416 services and deployed 25 bridge agents onto rented GPU instances. Its described bridge-agent model rents a container on the target's physical host to scan the Docker bridge network.
  • The agent source describes credential harvesting, stored XSS injection into Caddy auth proxy error logs to steal session tokens, access to unprotected Jupyter notebooks, and cryptocurrency-miner deployment. The report confirms one root shell on a victim's Jupyter notebook but says no miners had been planted.
  • Seventeen panel API endpoints required no authentication. The /agent/code.tar.gz endpoint exposed the complete C2 agent source, including hardcoded default credentials that granted full panel access.
Defensive Notes
  • Audit vast.ai Caddy auth proxy configurations for the bypass associated with the reported root-shell access.
  • Monitor rented containers for scans of 172.17.0.0/16 on the Docker bridge.
  • Treat rented instances that download code from 69.48.229.140 as hostile.
  • Report the operator's infrastructure to its hosting provider.

Indicators of compromise

TypeIndicatorContext
IPV469[.]48[.]229[.]140Operator infrastructure contacted by the npm packages on installation; it also hosted the VHX Harvester panel.

MITRE ATT&CK

Products

Tools

Industries

Related Articles