logo

Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System

ID: 80d36882-accb-5f08-931f-b7df0bd71ea2

STIX ID: report--80d36882-accb-5f08-931f-b7df0bd71ea2

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-06-09

Date Updated: 2026-07-24

...
...

This report analyzes the Miasma supply-chain campaign that implants install-time backdoors in packages by abusing node-gyp's binding.gyp parsing (command expansions, Python eval sandbox escapes, includes, dependencies, compiler hijacking, actions/rules). The technique enables silent execution during npm install — harvesting cloud credentials, CI tokens, SSH keys and persisting via auto-includes — and is difficult to detect by casual review of package.json, representing a high-risk, widely applicable attack vector against developer ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.