logo

Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem

ID: 7d492963-0847-5c83-8a87-6f57d261d7c4

STIX ID: report--7d492963-0847-5c83-8a87-6f57d261d7c4

Feed Name: Socket Blog

Threat Score
88/100

Date Published: 2026-06-25

Date Updated: 2026-07-03

Author: Socket Research Team

...
...

Socket Threat Research documents an active, sophisticated supply-chain campaign (Mini Shai-Hulud / Miasma / Hades) that poisoned numerous npm packages (LeoPlatform/RStreams ecosystem) and a Verana Blockchain Go module to run obfuscated Bun-staged JavaScript payloads via binding.gyp and IDE/AI-agent hooks; the malware steals a broad set of developer and CI/CD secrets, abuses GitHub Actions (including dead-drop behavior marked by strings like "RevokeAndItGoesKaboom"), and includes detailed IOCs and defensive remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.