Miasma is a malware and supply-chain intrusion cluster associated with self-propagating compromises of open-source software ecosystems, especially npm, PyPI, and GitHub-hosted developer workflows. It is widely discussed alongside the related Mini Shai-Hulud and Hades clusters, and some reporting characterizes Hades as an evolution of Miasma. Other reporting notes that Miasma itself has been described as a rebrand or variant of Mini Shai-Hulud. Attribution to a specific state sponsor is not established in the available reporting. The activity targets software maintainers, CI/CD environments, developer workstations, cloud-connected build systems, and downstream users of compromised packages and repositories. Observed victim sectors and themes include enterprise software, cloud tooling, Microsoft and Azure-related repositories, Red Hat-associated npm packages, AsyncAPI packages, and bioinformatics and computational biology ecosystems. The campaign abuses trusted publishing channels rather than exploiting registry platform flaws, typically relying on compromised maintainer credentials, stolen publish tokens, GitHub account access, or workflow abuse. Miasma-linked operations are notable for worm-like propagation. Reported propagation paths include republishing trojanized packages with stolen registry credentials, poisoning GitHub repositories and pull-request branches, abusing GitHub Actions and OIDC trusted publishing flows, and using harvested credentials to spread into additional developer assets. Some variants reportedly search public GitHub commits for attacker-controlled markers, use GitHub as command-and-control and exfiltration infrastructure, and maintain persistence through background services or startup modifications. Capabilities attributed across Miasma-related reporting include credential theft from GitHub, npm, PyPI, Cargo, RubyGems, JFrog, AWS, Azure, and GCP; collection of local environment data; theft of Kubernetes material, SSH keys, Docker configuration, shell histories, and .env content; remote command execution; persistence; lateral movement over SSH or cloud management channels; and package or repository mutation for onward spread. Several reports also describe memory-scraping components aimed at extracting secrets from CI runners and developer processes, as well as destructive logic such as token-revocation-triggered wiping in some Hades-linked builds. Tradecraft associated with the cluster includes multi-stage loaders, heavy JavaScript obfuscation, encrypted payload modules, signed tasking, fallback communications, anti-analysis checks for virtualized or instrumented environments, and selective termination on Russian locale settings. Some samples and campaigns also include prompt-injection or fake instruction blocks intended to disrupt LLM-assisted malware analysis and AI-enabled developer tooling. Miasma-branded artifacts, strings, and persistence names have been observed in malware code and configuration, but at least some incidents explicitly caution that such branding may be reused, imitated, or planted as misdirection rather than proving common authorship. Known related names and sub-clusters include Mini Shai-Hulud, Shai-Hulud, Hades, and TeamPCP-linked activity. The exact boundaries between these labels are not fully settled across public reporting, but Miasma is consistently used to describe an aggressive, evolving software supply-chain threat focused on credential theft, repository and package compromise, and recursive propagation through developer trust relationships.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior campaign that the malware appears to mimic for misdirection; the report explicitly says the current attack is not attributed to it.
Branding and artifact naming overlap with an earlier Miasma toolkit, but the content explicitly says attribution is inconclusive and may reflect code reuse, imitation, or deliberate mislabeling.
Supply-chain credential theft campaign delivered through compromised npm packages and developer accounts, using multi-stage droppers to steal GitHub, npm, and cloud credentials and upload stolen data to GitHub.
A named worm or malware cluster referenced in a report about malicious PyPI wheels targeting bioinformatics and MCP developers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.