Executive brief
An attacker compromised the OpenSearch Project's build infrastructure and injected malicious code into four releases of a widely-used Node.js client library for OpenSearch (a popular open-source search engine). Systems that installed the compromised package versions gain complete control by the attacker, allowing them to steal credentials, modify data, and disable services. Organizations using these specific versions must immediately isolate affected systems, revoke all credentials, and reinstall the library from a clean source.
Technical details
This is a supply-chain attack (CWE-506: Embedded Malicious Code) involving unauthorized access to the OpenSearch Project's CI/CD infrastructure. An external actor obtained force-push permissions and used them to embed malware into the npm package @opensearch-project/opensearch in versions 3.5.3, 3.6.2, 3.7.0, and 3.8.0, published on May 11-12, 2026 UTC. The attack vector is network-based (via npm package installation); user interaction is required (developer must install or update the package). An attacker can achieve arbitrary code execution on the host system with the privileges of the user running the Node.js application. The advisory indicates no patch is available; affected versions must be removed and replaced with uncompromised builds after infrastructure remediation.
Affected products
- OpenSearch Project @opensearch-project/opensearch 3.5.3, 3.6.2, 3.7.0, 3.8.0
Timeline
- 2026-05-19: disclosed: Advisory published on GitHub
- 2026-05-12: exploited: Malicious packages published to npm between 2026-05-12T00:29:34Z and 2026-05-12T00:47:39Z (UTC)