Miasma is a self-propagating JavaScript-based supply-chain worm and a variant of Mini Shai-Hulud, associated in reporting with TeamPCP activity. It has spread through malicious npm and PyPI package releases, harvesting developer, cloud, CI/CD, source-control, SSH, browser, cryptocurrency-wallet, and password-store credentials. Miasma can use stolen publishing credentials to infect additional packages, poison development-tool and AI coding-assistant configuration, and exfiltrate collected data through attacker-controlled repositories and command-and-control channels.
Miasma uses obfuscated, multi-stage payloads and execution mechanisms intended to evade conventional lifecycle-script checks, including build-configuration command substitution and import-time loaders. It can establish persistence through user-level services and AI-assisted development environment hooks, enabling later execution when coding sessions or projects are opened. The malware has also been observed extracting GitHub Actions secrets from runner-process memory. Miasma-associated modular runtimes support remote command execution, file transfer, payload updates, and resilient command-and-control using conventional web traffic and decentralized services. The family has affected Node.js developer workstations and CI/CD environments across Linux, macOS, and Windows; technical overlap does not conclusively attribute every Miasma-associated incident to TeamPCP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.”
The GitHub fingerprint the attackers left behind – a repository description reading “Alright Lets See If This Works” turned up on over 320 infected repositories before researchers began pulling the thread. That string is not something random. In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
The GitHub fingerprint the attackers left behind – a repository description reading “Alright Lets See If This Works” turned up on over 320 infected repositories before researchers began pulling the thread. That string is not something random. In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
An infrastructure provider's networks have been breached and they were dealing with the Miasma worm. That worm, as it turns out, is pretty hard to catch and delete because it is self-spreading through IDE configuration settings and through AI assisted environments.
An infrastructure provider's networks have been breached and they were dealing with the Miasma worm. That worm, as it turns out, is pretty hard to catch and delete because it is self-spreading through IDE configuration settings and through AI assisted environments.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
If either of those repository names appears in your GitHub organization, the worm created it using stolen credentials.
TeamPCP actors have conducted large-scale software supply chain compromises by targeting widely used developers and security tools, gaining access to victim environments and extracting sensitive data
Attackers then pushed poisoned commits and let the project’s own trusted publishing path release the malware under a valid npm identity.
TeamPCP allegedly inserted malicious code into software hosted on public repositories, which was then unwittingly used by other developers. The group injected malicious code into legitimate software packages and pushed trojanized versions through normal distribution channels.
For each one it finds, it injects a hook command which helps the malware stay persistent... every time the developer starts an AI coding session, the malware runs silently and automatically.
If either of those repository names appears in your GitHub organization, the worm created it using stolen credentials.
The attack began with a vulnerable GitHub Actions configuration that allowed untrusted pull request content to interact with a privileged workflow context. This gave the attacker a path to obtain or abuse an AsyncAPI automation identity and make unauthorized repository changes.
If either of those repository names appears in your GitHub organization, the worm created it using stolen credentials.
The bootstrapper writes an obfuscated JavaScript payload named _index.js. The Miasma lineage uses JavaScript-based obfuscation engines to make behavioral sandboxing and traditional signature-based detection difficult.
Active credential-stealing campaigns, such as Mini Shai-Hulud, Miasma, and Hades, embedding fake headers specifically engineered to fool AI-assisted review tools into marking code as benign.
including direct extraction from runner process memory via /proc/*/mem
harvests AWS, GCP, and Azure credentials | harvests AWS, GCP, and Azure credentials, GitHub Actions secrets
On disk the framework searches familiar files such as .npmrc, AWS credentials, kubeconfig, SSH private keys, Vault tokens, .netrc, Docker config, and Google service account JSON.
It looks for more than one hundred environment variable names spanning source control, package registries, major cloud providers, container platforms, secret managers, and popular AI services.
The second stage delivers a modular runtime called Miasma. That framework can talk to remote servers... Primary control servers sat at a single IP on ports 8080, 8081, and 8091, with fallback discovery over several decentralized networks.
When triggered, the script performs basic network checks and retrieves the Bun JavaScript runtime binary, saving it under ~/.bun.
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
98 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware campaign that uses fake headers intended to cause AI-assisted reviewers to classify malicious code as benign.
A Mini Shai-Hulud variant that spread through npm and PyPI registries while harvesting credentials and poisoning configuration files.
A malware lineage associated with JavaScript-based obfuscation. In this incident, the payload uses a downloaded Bun runtime to execute an obfuscated JavaScript credential-harvesting payload that collects environment variables, package-registry tokens, cloud credentials, and SSH keys and exfiltrates them over HTTP POST.
Multi-wave supply-chain campaign that abused an OIDC publishing endpoint, used a binding.gyp method to evade install-script detection, and later poisoned PyPI wheels using .pth startup execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.