Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System
ID: 80d36882-accb-5f08-931f-b7df0bd71ea2
STIX ID: report--80d36882-accb-5f08-931f-b7df0bd71ea2
Feed Name: Aikido Security's Blog
This report analyzes the Miasma supply-chain campaign that implants install-time backdoors in packages by abusing node-gyp's binding.gyp parsing (command expansions, Python eval sandbox escapes, includes, dependencies, compiler hijacking, actions/rules). The technique enables silent execution during npm install — harvesting cloud credentials, CI tokens, SSH keys and persisting via auto-includes — and is difficult to detect by casual review of package.json, representing a high-risk, widely applicable attack vector against developer ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
