Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit GitHub Actions to Insert Miasma Malware

Hackers Exploit GitHub Actions to Insert Miasma Malware

Posted on July 22, 2026 By CWS

A recent supply chain attack has leveraged GitHub Actions to introduce the Miasma malware into widely used AsyncAPI npm packages. This breach poses significant risks to developer environments and automated systems. By exploiting a compromised release process, attackers have managed to distribute malicious code via the project’s legitimate npm namespace, impacting approximately 2.9 million weekly downloads.

Exploiting Trusted Channels

The attackers successfully infiltrated the release process, utilizing trusted software pathways to propagate a Node.js payload associated with Miasma. As reported by Cato Networks to Cyber Security News, this campaign highlights the inadequacy of relying solely on valid package names and official workflows for security. The incident underscores the potential for adversaries to target automation processes to access sensitive data and downstream projects.

The breach began with a misconfigured GitHub Actions setup that allowed unverified pull request content to manipulate a privileged workflow context. This vulnerability provided attackers a means to alter AsyncAPI repository content, masquerading the malicious changes as typical development activities.

Malicious Code Distribution

Once embedded in a branch linked to the project’s release process, the malicious changes were published by AsyncAPI’s automation, lending them a veneer of legitimacy. This tactic differentiates the incident from traditional typosquatting, where attackers publish deceptively similar packages under unfamiliar accounts. It also resonates with previous vulnerabilities identified in GitHub Actions workflows, which can expose critical tokens and cloud credentials.

The affected npm packages, including versions like @asyncapi/generator 3.3.1 and @asyncapi/specs 6.11.2-alpha.1, were automatically incorporated into environments restoring dependencies during the breach period.

Stealthy Malware Execution

Unlike typical npm lifecycle scripts, the embedded JavaScript executed upon module import, remaining dormant post-installation. This stealthy execution model allows the malware to activate during various tasks, such as application runs or CI/CD jobs, evading standard detection measures.

The initial code executed a detached Node.js process, fetching an encrypted payload from IPFS. This payload enabled persistent access, remote command execution, and interaction with attacker-controlled infrastructure, using an Ethereum contract for fallback command-and-control configurations.

Recommendations for Security Measures

Organizations should scrutinize their manifests, lockfiles, and build artifacts for compromised versions to assess potential exposure. Security teams are advised to inspect outbound connections, review repository logs, and rotate credentials. Additionally, enhancing privileged workflow security, particularly those involving pull_request_target, is crucial.

Indicators of compromise have been detailed, including specific npm package versions and network signatures. These indicators should be incorporated into monitoring strategies to detect and mitigate similar threats effectively.

The attack serves as a stark reminder of the vulnerabilities inherent in automation processes and the necessity of robust security measures to safeguard against sophisticated threats in software ecosystems.

Cyber Security News Tags:AsyncAPI, automation security, CI/CD pipelines, Cybersecurity, developer tools, GitHub, GitHub actions, JavaScript, Malware, Miasma RAT, Node.js, npm packages, Software Security, supply chain attack, Vulnerability

Post navigation

Previous Post: AI Safety Leadership in Flux as Director Resigns
Next Post: Chrome Update Resolves Critical Security Flaws

Related Posts

Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents Cyber Security News
Infamous Cybercriminal Forum BreachForums Is Back Again With A New Clear Net Domain Infamous Cybercriminal Forum BreachForums Is Back Again With A New Clear Net Domain Cyber Security News
ShinyHunters Allegedly Breaches Cisco Data ShinyHunters Allegedly Breaches Cisco Data Cyber Security News
Critical GitLab Security Updates Address Key Vulnerabilities Critical GitLab Security Updates Address Key Vulnerabilities Cyber Security News
Top 10 Best Practices for Securing Your Database Top 10 Best Practices for Securing Your Database Cyber Security News
Hackers Exploit Microsoft 365 to Divert Payments Hackers Exploit Microsoft 365 to Divert Payments Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark