discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Miasma malware targets npm packages and GitHub Actions in a supply chain attack, compromising developer credentials and spreading across package registries. The attack affects multiple packages, including LeoPlatform and RStreams, and uses various tactics to steal secrets…

By Ravie Lakshmanan·Jun 26·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Image: thehackernews.com

The Miasma malware campaign has evolved to target npm packages and GitHub Actions, using techniques such as npm registry poisoning and GitHub Actions secret theft to harvest developer credentials and spread across package ecosystems.

Why it matters

This attack matters because it highlights the vulnerability of supply chains to malware attacks, and the potential for widespread compromise of developer credentials and package ecosystems. It also underscores the importance of securing developer workflows and package registries.

Imagine you have a big box of toys, and someone puts a bad toy in the box that can steal your secrets. That's kind of what's happening with the Miasma malware, which is putting bad code in packages that developers use, so it can steal their credentials and spread to other packages.

Analysis

Introduction to Miasma Malware

The Miasma malware campaign has been identified as a significant threat to package ecosystems, including npm and GitHub. The campaign has evolved to use various tactics to steal developer credentials and spread across package registries, repositories, and trusted developer workflows.

The latest activity includes malicious npm releases affecting multiple packages, including LeoPlatform and RStreams, as well as GitHub Actions workflow abuse and a related Go module compromise involving the Verana Blockchain project. The end goal of the campaign is to harvest developer or maintainer credentials and weaponize the stolen data to spread across package ecosystems.

Tactics and Techniques

The Miasma malware campaign uses a range of tactics and techniques to achieve its goals, including npm registry poisoning, binding.gyp install-time execution, Bun-staged JavaScript malware, GitHub dead-drop infrastructure, GitHub Actions secret theft, IDE and AI coding assistant persistence, and encrypted credential exfiltration.

The malicious npm packages incorporate a binding.gyp file to execute arbitrary code during installation, resulting in the launch of a JavaScript loader that downloads and installs the Bun runtime if not present, and then initiates the stealer payload responsible for harvesting secrets, credentials, and tokens.

Impact and Implications

The impact of the Miasma malware campaign is significant, with the potential for widespread compromise of developer credentials and package ecosystems. The campaign highlights the vulnerability of supply chains to malware attacks, and the importance of securing developer workflows and package registries.

The compromise of the Verana GitHub repository expands the scope of the campaign beyond npm, and reinforces the larger campaign theme: Miasma is moving across package ecosystems by targeting developer workflows, not just package-manager install hooks. This reinforces the need for developers to be vigilant in securing their workflows and package registries, and for organizations to implement robust security measures to protect against supply chain attacks.

Key points

  • Miasma malware targets npm packages and GitHub Actions
  • The campaign uses various tactics to steal developer credentials and spread across package ecosystems
  • The compromise of the Verana GitHub repository expands the scope of the campaign beyond npm
The Upside

The discovery of the Miasma malware campaign highlights the importance of securing package ecosystems and developer workflows. By implementing robust security measures, such as multi-factor authentication and regular package audits, developers and organizations can reduce the risk of compromise and protect against supply chain attacks.

The Downside

The Miasma malware campaign has the potential to cause significant damage to package ecosystems and developer workflows. If left unchecked, the campaign could lead to widespread compromise of developer credentials and package ecosystems, resulting in significant financial and reputational losses for affected organizations.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarenpmgithubsupply-chain-attack

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 26, 2026

Source

thehackernews.com

Share

Topics

securitymalwarenpmgithubsupply-chain-attack

Related

More from this desk

Aug 17·bleepingcomputer.com

Microsoft Confirms GitHub is Down Worldwide

GitHub is experiencing a widespread outage, causing errors across the website, API, Actions, Pull Requests, and other services. Microsoft confirmed the outage and is investigating the cause.

Aug 17·bleepingcomputer.com

Certighost and the Privilege Hiding in Your Certificate Authority

A vulnerability in the Certification Authority (CA) in Active Directory environments allows a low-privileged user to obtain a valid authentication certificate for a Domain Controller, which can be used to become the Domain Controller. This is a trust-validation problem th…

Aug 17·thehackernews.com

Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

This week's cybersecurity news includes suspected China APT behind VMware exploitation, Apple macOS flaw exploited to drop crypto miner, Lazarus Group exploiting Windows 0-day, GeoServer patches critical flaw under attack, and Amnesia Stealer targeting macOS users.

Aug 17·bleepingcomputer.com

Windows Server 2022 reaches end of mainstream support in 60 days

Microsoft warns IT admins that Windows Server 2022 mainstream support ends October 13, 2026, shifting to extended security updates through October 14, 2031.