logo

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

ID: 47021ddc-75f0-5e03-bbb0-f6f509b51394

STIX ID: report--47021ddc-75f0-5e03-bbb0-f6f509b51394

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: [email protected] (The Hacker News)

...
...

Researchers report an active cross-ecosystem supply-chain campaign (linked to the Shai-Hulud / Miasma / Hades families) that trojanized numerous npm packages and a Go module to install a Bun-based loader and an infostealer that harvests developer credentials, GitHub/OIDC tokens, and CI/CD secrets, then exfiltrates and uses those credentials to spread via package registries and GitHub Actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.