Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageDevSecOps Desk
DevSecOps

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

The Miasma malware family has expanded from npm into Go packages and now abuses GitHub Actions workflows, demonstrating how polyglot supply-chain attacks can propagate across multiple ecosystems simultaneously.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem.

"The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go

Editorial Analysis

Why it matters

Enterprises running mixed-language stacks face compounding risk: a single campaign now poisons npm, Go modules, and CI/CD pipelines in parallel, undermining trust in multiple dependency channels at once.

What to do

Audit GitHub Actions workflows for unexpected third-party action references and enforce allow-listing of trusted actions; scan npm and Go dependencies for known Miasma-family IOCs.

Board brief

A supply-chain attack campaign now spans multiple programming ecosystems and CI/CD systems, broadening exposure for software-producing organisations.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the DevSecOps Desk