Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
The Miasma malware family has expanded from npm into Go packages and now abuses GitHub Actions workflows, demonstrating how polyglot supply-chain attacks can propagate across multiple ecosystems simultaneously.
Summary written by editorial AI · Source link below
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem.
"The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go
Editorial Analysis
Enterprises running mixed-language stacks face compounding risk: a single campaign now poisons npm, Go modules, and CI/CD pipelines in parallel, undermining trust in multiple dependency channels at once.
Audit GitHub Actions workflows for unexpected third-party action references and enforce allow-listing of trusted actions; scan npm and Go dependencies for known Miasma-family IOCs.
A supply-chain attack campaign now spans multiple programming ecosystems and CI/CD systems, broadening exposure for software-producing organisations.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the DevSecOps Desk
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT17 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul