Miasma
Coverage of Miasma in the Nexus archive.
- Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
The Miasma malware campaign has poisoned over 20 npm packages in the Leo Platform and RStreams ecosystems, targeting developer credentials and CI environments. The attack, executed in under three seconds by compromising an npm maintainer account, steals secrets from cloud providers, GitHub, and other platforms, and republishes packages to propagate further.
- The ‘Miasma’ worm source code briefly leaked on GitHub
The Miasma credential-stealing attack framework's source code was briefly leaked on GitHub. It has been used to target open-source ecosystems through supply-chain attacks.
- Miasma worms its way onto GitHub as attack kit goes open source
The Miasma worm, a supply-chain attack toolkit, was open-sourced on GitHub via compromised developer accounts, enabling attacks on public registries and repositories. SafeDep identified the malicious repositories, which allow credential-based attacks on platforms like PyPI, npm, and GitHub, following a pattern similar to TeamPCP's earlier mini Shai-Hulud worm. The release has raised concerns about supply-chain security, with 473 affected package artifacts tracked by Socket.
- Red Hat npm packages compromised to steal developer credentials
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma'.
- Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
A supply chain attack named Miasma has compromised Red Hat npm packages, using a credential-stealing worm with tactics similar to the Mini Shai-Hulud campaign. The attack includes install-time execution, credential harvesting, and encrypted data exfiltration.