Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
ID: 2df025e6-a926-5045-8b91-d975ce734088
STIX ID: report--2df025e6-a926-5045-8b91-d975ce734088
Feed Name: Socket Blog
Socket Threat Research reports a supply-chain compromise of @immobiliarelabs Backstage plugins published on June 26, 2026 as part of the Miasma Mini Shai‑Hulud campaign. Malicious root-level index.js loaders, a shared binding.gyp republish trick, Bun-executed multi-stage payloads, and compromised GitHub Actions were used to steal environment and CI/CD secrets, create exfiltration repositories, and propagate further; the report lists affected package versions, SHA‑256 hashes, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
