SECURITYTHE REGISTER
Miasma worms its way onto GitHub as attack kit goes open source
The Miasma worm, a supply-chain attack toolkit, was open-sourced on GitHub via compromised developer accounts, enabling attacks on public registries and repositories. SafeDep identified the malicious repositories, which allow credential-based attacks on platforms like PyPI, npm, and GitHub, following a pattern similar to TeamPCP's earlier mini Shai-Hulud worm. The release has raised concerns about supply-chain security, with 473 affected package artifacts tracked by Socket.
Mentioned
Related Signal
Adjacent reporting
- Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
- Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack
- The never-ending supply chain attacks worm into SAP npm packages, other dev tools
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
- Another npm supply chain worm is tearing through dev environments
- Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise