logo

Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages

ID: 56d44851-4501-521a-96e2-41c0c028e25d

STIX ID: report--56d44851-4501-521a-96e2-41c0c028e25d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Tushar Subhra Dutta

...
...

Miasma is a sophisticated supply-chain malware campaign that published malicious versions of over 20 npm packages (and a linked Go module) to execute obfuscated JavaScript via binding.gyp/node-gyp and a Bun-based payload, stealing a wide range of developer secrets (tokens, SSH keys, cloud creds, AI assistant settings) and poisoning repositories and CI workflows; the report includes numerous IoCs (SHA-256 hashes, filenames, package names, campaign strings) and remediation steps such as secret rotation, rebuilding from clean lockfiles, and pinning GitHub Actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.