Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages
ID: 56d44851-4501-521a-96e2-41c0c028e25d
STIX ID: report--56d44851-4501-521a-96e2-41c0c028e25d
Feed Name: cybersecurityNews.com
Miasma is a sophisticated supply-chain malware campaign that published malicious versions of over 20 npm packages (and a linked Go module) to execute obfuscated JavaScript via binding.gyp/node-gyp and a Bun-based payload, stealing a wide range of developer secrets (tokens, SSH keys, cloud creds, AI assistant settings) and poisoning repositories and CI workflows; the report includes numerous IoCs (SHA-256 hashes, filenames, package names, campaign strings) and remediation steps such as secret rotation, rebuilding from clean lockfiles, and pinning GitHub Actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
