logo

Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages

ID: 2df025e6-a926-5045-8b91-d975ce734088

STIX ID: report--2df025e6-a926-5045-8b91-d975ce734088

Feed Name: Socket Blog

Threat Score
80/100

Date Published: 2026-06-26

Date Updated: 2026-07-03

Author: Socket Research Team

...
...

Socket Threat Research reports a supply-chain compromise of @immobiliarelabs Backstage plugins published on June 26, 2026 as part of the Miasma Mini Shai‑Hulud campaign. Malicious root-level index.js loaders, a shared binding.gyp republish trick, Bun-executed multi-stage payloads, and compromised GitHub Actions were used to steal environment and CI/CD secrets, create exfiltration repositories, and propagate further; the report lists affected package versions, SHA‑256 hashes, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.