Researchers reported that the Miasma malware family is expanding from software supply-chain compromise into AI-assisted development environments, using trusted tooling to gain persistence, steal credentials, and sabotage systems. Tenable linked the campaign to Mini Shai-Hulud and a Miasma variant that modifies AI coding assistant configuration and rules files, adding SessionStart hooks and prompt-injection content so malicious actions run automatically when developers launch tools such as Claude Code, Gemini CLI, GitHub Copilot, Cursor, ChatGPT Codex, Cline, and Aider. WIRED, citing CrowdStrike research, said the malware is built to burrow into AI infrastructure, exfiltrate sensitive data, deepen access, and in some cases trigger a destructive "death switch" that locks out users while wiping or damaging files.
Semgrep separately detailed a related supply-chain intrusion in which an attacker gained push access to the asyncapi/generator repository’s next branch and used the project’s legitimate GitHub Actions release workflow to publish malicious npm packages with valid SLSA provenance through npm’s trusted-publisher integration. Affected packages included @asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and later @asyncapi/specs; they contained an obfuscated dropper that executed on require(), launched a hidden Node.js process, fetched a second-stage payload from IPFS, and deployed Miasma v3. The malware sought GitHub, npm, PyPI, AWS, Kubernetes, SSH, browser, and macOS Keychain secrets, underscoring how attackers are abusing both package ecosystems and AI agent harness files as high-trust, low-visibility footholds in developer environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Research reported on July 21, 2026 described the Mini Shai-Hulud campaign and its Miasma variant as targeting developer environments by modifying AI coding assistant configuration and rules files for persistence and automatic malicious execution. The reporting said the malware sought credentials, deeper access, data exfiltration, and in some cases destructive effects including a lockout-and-wipe 'death switch.'
On July 14, 2026, an attacker with push access to the asyncapi/generator repository’s next branch used the project’s legitimate GitHub Actions release workflow and npm trusted-publisher integration to publish malicious packages with valid SLSA provenance. The compromised packages included @asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and later @asyncapi/specs, carrying an obfuscated dropper that fetched and deployed Miasma v3.
On June 4, 2026, Semgrep reported that the self-propagating Miasma v2 npm malware had compromised 57 packages across more than 286 malicious versions. The report said the worm used a malicious binding.gyp file to execute during npm install without lifecycle scripts, and detailed credential theft, AI-assistant persistence, forged provenance, and published IOCs and affected package lists.
On May 18, 2026, Semgrep reported a supply-chain compromise of an npm maintainer that led to malicious dependencies being injected into widely used packages including the @antv/* namespace, timeago.js, and size-sensor. The exposure window enabled further spread across hundreds of npm ecosystem packages, consistent with renewed Mini Shai-Hulud worm activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcewired.com
Open sourcesemgrep.dev
Open sourcesemgrep.dev
Open sourcesemgrep.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.