Miasma Mini Shai-Hulud is a software supply-chain threat cluster focused on compromising trusted developer infrastructure and republishing legitimate open-source packages with malicious code. The activity has been associated with repeated compromises affecting npm and other software distribution ecosystems, including campaigns involving package families tied to LeoPlatform, RStreams, Verana, and ImmobiliareLabs. The actor’s tradecraft centers on poisoning widely trusted development dependencies and release paths in order to gain execution inside developer workstations, build systems, and CI/CD environments. The actor has targeted developer-oriented software components, including Backstage plugins used for GitLab integration and LDAP authentication. In observed operations, multiple historical package versions were republished maliciously, indicating an effort to maximize reach across organizations pinned to older dependency branches. The malware delivery chain has used concealed JavaScript loaders, staged decryption, and execution via Bun, as well as a Phantom Gyp technique that triggers malicious code through node-gyp-related build behavior rather than conventional install hooks. Post-compromise behavior includes theft of developer and cloud secrets, collection of environment files and authentication material, abuse of GitHub Actions workflows, and propagation into additional repositories using stolen access. The actor has also demonstrated persistence-oriented behavior by planting hooks in developer tooling such as IDE extensions and AI coding assistant plugins. Exfiltration has been conducted through attacker-controlled repositories using the GitHub API. A recurring campaign marker has linked this activity to earlier Miasma operations. The actor’s victimology is centered on software development and internal platform engineering environments rather than direct exploitation of the business applications represented by the trojanized packages. The operational objective appears to be broad credential theft and downstream compromise through trusted software and automation channels. A plausible upstream intrusion path through compromised release automation has been noted in connection with some activity, but that access path remains unconfirmed. Based on the observed emphasis on secret theft, CI/CD abuse, and repository propagation, Miasma Mini Shai-Hulud is best characterized as a financially motivated supply-chain actor with strong post-exploitation capability in developer ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.