logo

It’s In Your AI Assistant Now: Shai-Hulud Wave 3 and the Miasma Worm Targeting npm

ID: 2bedc158-c667-5142-9dcd-a752130f30eb

STIX ID: report--2bedc158-c667-5142-9dcd-a752130f30eb

Feed Name: Morphisec Blog

Threat Score
90/100

Date Published: 2026-06-08

Date Updated: 2026-07-20

...
...

Miasma (Wave 3) is a sophisticated, active supply-chain malware campaign that weaponizes binding.gyp to run via node-gyp during native builds, evades lifecycle-script monitoring, repackages compromised libraries with valid Sigstore attestations, and persists by injecting backdoors into developer AI assistant and IDE config files (.claude, .cursor, .gemini, .vscode and GitHub-related entries). It steals credentials across npm, GitHub, AWS, GCP, Azure, Vault, Kubernetes, SSH keys and password managers, self-replicates across ecosystems (npm, RubyGems, GitHub), and demonstrates sandbox-aware evasion and a 48-hour dormancy timer—making detection and conventional remediation (npm uninstall, node_modules removal) insufficient.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.