logo

Miasma worms its way onto GitHub as attack kit goes open source

ID: b80e0ada-3d9e-5c6e-a3f5-4553667c6e71

STIX ID: report--b80e0ada-3d9e-5c6e-a3f5-4553667c6e71

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-06-09

Date Updated: 2026-06-10

...
...

The article reports that the Miasma supply-chain worm toolkit was publicly released on GitHub, enabling package registry poisoning and GitHub-native command-and-control; it leverages stolen personal access tokens (PATs) encrypted in commit messages, delivers immediate JavaScript via commit checks, and fetches Python persistence scripts, with hundreds of package artifacts already impacted and serious detection challenges for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.