Security researchers reported multiple self-propagating npm supply-chain malware campaigns that used compromised maintainer accounts and poisoned package updates to infect developer and CI/CD environments. JFrog said IronWorm was distributed through 36–37 malicious npm packages republished from the compromised asteroiddao account, where preinstall hooks launched a Rust ELF payload on Linux. The malware stole credentials and secrets tied to AWS, npm, SSH, Vault, OpenAI, Anthropic, Kubernetes, and Exodus wallets, hid with an eBPF rootkit, and used Tor for command-and-control. Investigators also linked the activity to poisoned GitHub repositories across nine organizations, including backdated malicious commits attributed to spoofed automation identities such as claude, dependabot[bot], renovate[bot], and github-actions[bot].
A separate but related wave, tracked by Sonatype as Shai-Hulud "Miasma", pushed 281 malicious npm package versions and used binding.gyp with node-gyp to execute during installation, bypassing defenses that only inspect lifecycle scripts. Like IronWorm, the malware harvested developer and CI/CD secrets, validated stolen access, and republished trojanized versions of legitimate packages to continue spreading through repositories, build systems, and registries. Researchers said active exploitation was observed in the wild and warned that public impact may understate the full scope, particularly where private projects and CI runners were exposed through trusted publishing flows and compromised maintainer credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
20 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-26, multiple npm packages maintained by Immobiliare Labs were found compromised with a binding.gyp/node-gyp install-time payload affecting Backstage GitLab and LDAP authentication plugins. StepSecurity linked the malicious releases to the broader Miasma activity based on coordinated mass patch releases across branches, Bun-based staged malware, credential theft, AI tool persistence, and worm-like republishing functions targeting npm and PyPI.
Fortinet described an investigated cloud intrusion in which a suspected compromise of a Jenkins runner in May 2026 led to theft and external reuse of AWS instance-role credentials. The attacker created an IAM administrator user named cloudops-monitor, escalated privileges, modified cloud settings, enumerated secrets, and accessed Amazon Redshift via the Redshift Data API as part of staged exfiltration activity.
Socket.dev linked the Miasma threat cluster to related payloads in a Go module associated with the Verana Blockchain project, indicating the campaign expanded beyond npm into the Go ecosystem. The report connected this activity to the broader Mini Shai-Hulud and Hades malware cluster.
Sonatype reported that the Leo Platform and RStreams Miasma variant no longer relied on npm installation hooks, instead concealing payload execution elsewhere in the installation process. The researchers also said the malware downloaded and executed the Bun JavaScript runtime, marking an evolution in the campaign's tradecraft.
A new supply-chain wave linked to the Shai-Hulud/Miasma family compromised a developer account and published 23 malicious npm packages in the LeoPlatform and RStreams ecosystems. The packages executed malware during npm install on developer machines and CI/CD runners, using Phantom Gyp-style binding.gyp execution, Bun-staged payloads, and GitHub-based credential exfiltration.
Ox Security said the earliest identified commit tied to the new Shai-Hulud / Miasma / Hades npm wave contained the string "Alright Lets See If This Works" and appeared on GitHub on 2026-06-24. The campaign used compromised GitHub accounts to host payloads and was associated with hundreds of repositories containing stolen credentials.
Deep Specter Research said GitHub dismissed two formal vulnerability reports concerning client-supplied commit timestamps and unverified author metadata, which researchers argue help Shai-Hulud variants backdate malicious commits and impersonate trusted developers. GitHub reportedly classified the reports as ineligible and pointed to commit signing and Vigilant Mode as mitigations.
Researchers said the Miasma supply-chain attack toolkit was open sourced on GitHub via repositories named "Miasma-Open-Source-Release," likely through four previously compromised developer accounts. Wiz reported the release occurred on 2026-06-08 and described Miasma as a GitHub-centric toolkit for attacking package registries, repositories, CI workflows, and related developer infrastructure.
A report described a supply-chain attack on PyPI involving 37 malicious wheel files across 19 Python packages, using Python .pth startup hooks to execute malware when the interpreter initializes. The activity was linked to the Mini Shai-Hulud / Miasma lineage and used Python loaders to install the Bun runtime and run an obfuscated JavaScript payload for credential theft and exfiltration.
Sonatype Security Research reported a new wave of the Shai-Hulud campaign, dubbed "Miasma: The Spreading Blight," involving 281 malicious npm package versions. The variant abuses binding.gyp and node-gyp execution during npm install to steal credentials and propagate through compromised maintainer accounts, repositories, CI/CD systems, and registries.
After the campaign was discovered, the malicious npm package versions were deprecated. No CVE or vendor patch was issued because the incident involved intentional malicious package compromise rather than a software vulnerability.
JFrog reported that IronWorm was actively exploiting developer and CI environments, stealing credentials, deploying an eBPF rootkit for stealth, and communicating over Tor. The malware was also found capable of self-propagation by abusing npm Trusted Publishing OIDC flows on CI runners without requiring stored npm tokens.
The attackers poisoned GitHub repositories across nine organizations with backdated malicious commits using spoofed automation identities including claude, dependabot[bot], renovate[bot], and github-actions[bot]. JFrog observed 14 confirmed malicious commits publicly and 57 backdated malicious commits in total across the compromised organizations.
The IronWorm campaign began from a compromised npm account named "asteroiddao," which was used to republish dozens of malicious package versions that executed a Rust ELF payload via npm preinstall hooks. Reports describe 36 to 37 malicious packages tied to this compromise.
SlowMist reported a supply-chain poisoning incident affecting legitimate npm packages under the @redhat-cloud-services scope, identifying 32 packages and 96 malicious versions. The analysis linked the multi-stage preinstall malware to the Shai-Hulud family and described credential theft, GitHub workflow injection, npm self-propagation, and persistence capabilities.
Ox Security stated that the IronWorm activity was detected early and contained before it spread into more popular npm packages. This assessment was reported alongside broader analysis of the campaign's propagation methods and credential theft behavior.
During the June 3, 2026 Miasma campaign, GitHub reportedly disabled 73 compromised repositories within 105 seconds of detection, including 49 associated with Microsoft, Azure, and Azure-Samples. The action followed attackers' use of stolen GitHub personal access tokens and backdated commits to plant malicious files that abused developer tooling and AI coding agent workflows.
StepSecurity reported that on 2026-06-03 a 'Phantom Gyp' supply-chain attack compromised 57 npm packages across more than 286 malicious versions, including packages such as @vapi-ai/server-sdk and ai-sdk-ollama. The campaign used binding.gyp execution during npm install, exfiltrated secrets to attacker-controlled GitHub repositories under liuende501, and republished packages with forged SLSA provenance and Sigstore signing while also planting AI assistant backdoor files.
SlowMist reported that the official PyPI package mistralai==2.4.6 was maliciously poisoned, likely through compromise of the project's release pipeline or trusted publishing path rather than typosquatting. The Linux-targeting payload downloaded a second stage from 83.142.209.194, stole extensive secrets, and was linked to the Shai-Hulud framework through reuse of the same RSA public key.
A Medium post describes a September–October 2025 supply-chain compromise in which a development team was hit by malicious npm dependency updates and a force-pushed commit that inserted obfuscated code into SSR-executed files. The team said three of five developers had malicious processes running and another developer was infected by a different malware variant, prompting incident response actions including process termination, infrastructure blocking, code reversion, and credential rotation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
36 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourceresearch.jfrog.com
Open sourceslowmist.medium.com
Open sourcedocs.npmjs.com
Open sourceusmandev.medium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.