logo

The ‘Miasma’ worm source code briefly leaked on GitHub

ID: d8563e92-8e00-56a6-b945-cce3730f215f

STIX ID: report--d8563e92-8e00-56a6-b945-cce3730f215f

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Bill Toulas

...
...

Miasma, a worm‑like credential‑stealing framework that targets developer machines and open‑source supply chains, was deliberately published on GitHub; it harvests cloud, CI/CD, password manager and secret store credentials, abuses them to trojanize npm/PyPI/RubyGems packages and GitHub repositories/workflows, uses GitHub as its C2 channel, includes a destructive dead‑man switch that can wipe user data, and employs a multi‑stage, per‑build obfuscation/encryption pipeline to evade detection — the leak is likely to increase supply‑chain attacks and developers are advised to pin dependencies, delay adoption of new packages, and validate builds in isolated environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.