logo

binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts

ID: 7f069b36-edb4-56d7-b4a8-a0554116308d

STIX ID: report--7f069b36-edb4-56d7-b4a8-a0554116308d

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Tushar Subhra Dutta

...
...

**Executive summary:** StepSecurity and CSN describe a rapid, high‑sophistication npm supply‑chain campaign named “Phantom Gyp” that used a 157‑byte binding.gyp install hook to execute a self‑replicating Miasma worm during npm install, compromising 57 packages across 286 malicious versions (including widely downloaded SDKs); the malware harvests CI and cloud credentials, propagates by injecting and republishing packages with forged SLSA/Sigstore provenance, and plants AI assistant backdoors — the report includes extensive IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.