logo

Malicious binding.gyp Campaign Targets npm Packages Across Maintainer Accounts

ID: 56ffb179-cfd6-52e9-a47c-32bd6917588e

STIX ID: report--56ffb179-cfd6-52e9-a47c-32bd6917588e

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Varshini

...
...

On June 3, 2026, a coordinated npm supply-chain attack compromised 57 packages by embedding a tiny binding.gyp that triggered node-gyp to execute a 4.5 MB Miasma worm payload; the worm downloads the Bun runtime to evade detection, harvests AWS/GCP/Azure credentials and GitHub Actions secrets, installs backdoors targeting AI coding assistants, and exfiltrates stolen data to GitHub repositories, with multiple file hashes and IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.