Back
Adversary Intelligence
Table of Content
Vikas Kundu
A naturally curious mind driven by the need to understand how things work and how to make them better. Passionate about learning, experimenting, and exploring new ideas across technology and security.
No items found.

Executive Summary

The companion report GTI-TOPHIT documented 85 npm packages published under the @prime0 scope, all of which beaconed to 69.48.229.140:8080 on installation. That infrastructure has a second service on port 80. It is a purpose-built offensive panel called VHX Harvester, version 0.1.0, and it runs a live operation against the vast.ai GPU rental marketplace. As of 25 September 2026, the panel has enumerated 297 host IPs from the vast.ai public API, scanned 13,368 service endpoints across them, exfiltrated metadata from 416 services, deployed 25 bridge agents onto rented GPU instances, and achieved one confirmed root shell on a victim's Jupyter notebook. No cryptocurrency miners have been planted. The operator is still active: the panel's activity log shows continuous rent attempts against the vast.ai marketplace.

The panel was misconfigured that allowed a rare glimpse into the operation and full panel access. Seventeen of its API endpoints require no authentication, including /agent/code.tar.gz, which serves the complete C2 agent source code with hardcoded default credentials. Those credentials grant full panel access. The agent source reveals an eight-phase kill chain: enumerate GPU hosts from the vast.ai marketplace API, scan their port ranges, classify and fingerprint services, harvest credentials and metadata, inject stored XSS into vast.ai's Caddy auth portals to steal session tokens, rent cheap containers on the same physical host as the target to scan the Docker bridge network, access unprotected Jupyter notebooks for root shells, and deploy cryptocurrency miners onto hijacked GPU instances. GPU cloud cryptojacking is an established threat class, with at least six documented campaigns since 2023 including the CSA-reported ComfyUI botnet. VHX differs in three specifics that have no documented precedent: the bridge agent model, which rents legitimate containers on the same host as the target to scan the Docker bridge; stored XSS injection into the Caddy auth proxy’s error logs; and the use of npm typosquats as the discovery vector for GPU infrastructure.

The operation is in its development phase and has not achieved its stated objective. Defenders on vast.ai should audit their Caddy auth proxy configuration for the bypass that gave the operator a root shell, monitor for containers scanning 172.17.0.0/16 on the Docker bridge, and treat any rented instance that downloads code from 69.48.229.140 as hostile. The operator's own infrastructure should be reported to the hosting provider. This analysis was conducted without executing any attack functionality and without authenticating to any victim service.
‍

Click Here To Read Full Report

Related Blogs