Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker didn't steal an npm token or exploit a bug in GitHub Actions this time either. They gained push access to two source repositories and let each project's own release pipeline do the publishing.
an attacker gained push access to the asyncapi/generator repository's next branch and pushed a single malicious commit... This triggered the project's legitimate release-with-changesets.yml GitHub Actions workflow... packages... were published to npm with valid SLSA provenance attestations
spawning a detached, hidden Node.js process that downloads a second-stage payload from an IPFS gateway
When Node.js loads the modified module, the code starts a detached child process... It retrieves a second-stage file from an IPFS gateway, writes it into a user-profile directory under a plausible name, and starts it in the background.
Attackers placed an obfuscated block inside ordinary source files where network access and process creation would not be expected... When Node.js loads the modified module, the code starts a detached child process and allows the normal application or CI task to continue.
macOS persistence marker Node Auto-Update Script Shell startup-file persistence marker
the attacker didn't steal an npm token or exploit a bug in GitHub Actions this time either. They gained push access to two source repositories and let each project's own release pipeline do the publishing.
macOS persistence marker Node Auto-Update Script Shell startup-file persistence marker
the attacker didn't steal an npm token or exploit a bug in GitHub Actions this time either. They gained push access to two source repositories and let each project's own release pipeline do the publishing.
Each package contained an identical... obfuscator.io-obfuscated dropper injected into a single source file, padded with ~1000 leading spaces to hide it from diff views.
the attacker didn't steal an npm token or exploit a bug in GitHub Actions this time either. They gained push access to two source repositories and let each project's own release pipeline do the publishing.
Stage 3 decrypts (AES-256-GCM plus a rotation cipher) into a 3.08 MB bundled application: Miasma RAT itself.
Its active command handler can run arbitrary shell commands, return output...
writes it to an OS-specific hidden directory disguised as a Node.js runtime folder
Attackers placed an obfuscated block inside ordinary source files where network access and process creation would not be expected... When Node.js loads the modified module, the code starts a detached child process and allows the normal application or CI task to continue.
Once it establishes itself on the system the payload then connects to a C2 server... Six independent C2 (command-and-control) channels - HTTP, Nostr relay, IPFS, BitTorrent DHT, a libp2p P2P mesh, and an Ethereum dead-drop contract
Six independent C2 (command-and-control) channels - HTTP, Nostr relay, IPFS, BitTorrent DHT, a libp2p P2P mesh, and an Ethereum dead-drop contract
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.