Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit GitHub Actions to Insert Miasma Malware

Hackers Exploit GitHub Actions to Insert Miasma Malware

Posted on July 22, 2026 By CWS

A recent supply chain attack has leveraged GitHub Actions to introduce the Miasma malware into widely used AsyncAPI npm packages. This breach poses significant risks to developer environments and automated systems. By exploiting a compromised release process, attackers have managed to distribute malicious code via the project’s legitimate npm namespace, impacting approximately 2.9 million weekly downloads.

Exploiting Trusted Channels

The attackers successfully infiltrated the release process, utilizing trusted software pathways to propagate a Node.js payload associated with Miasma. As reported by Cato Networks to Cyber Security News, this campaign highlights the inadequacy of relying solely on valid package names and official workflows for security. The incident underscores the potential for adversaries to target automation processes to access sensitive data and downstream projects.

The breach began with a misconfigured GitHub Actions setup that allowed unverified pull request content to manipulate a privileged workflow context. This vulnerability provided attackers a means to alter AsyncAPI repository content, masquerading the malicious changes as typical development activities.

Malicious Code Distribution

Once embedded in a branch linked to the project’s release process, the malicious changes were published by AsyncAPI’s automation, lending them a veneer of legitimacy. This tactic differentiates the incident from traditional typosquatting, where attackers publish deceptively similar packages under unfamiliar accounts. It also resonates with previous vulnerabilities identified in GitHub Actions workflows, which can expose critical tokens and cloud credentials.

The affected npm packages, including versions like @asyncapi/generator 3.3.1 and @asyncapi/specs 6.11.2-alpha.1, were automatically incorporated into environments restoring dependencies during the breach period.

Stealthy Malware Execution

Unlike typical npm lifecycle scripts, the embedded JavaScript executed upon module import, remaining dormant post-installation. This stealthy execution model allows the malware to activate during various tasks, such as application runs or CI/CD jobs, evading standard detection measures.

The initial code executed a detached Node.js process, fetching an encrypted payload from IPFS. This payload enabled persistent access, remote command execution, and interaction with attacker-controlled infrastructure, using an Ethereum contract for fallback command-and-control configurations.

Recommendations for Security Measures

Organizations should scrutinize their manifests, lockfiles, and build artifacts for compromised versions to assess potential exposure. Security teams are advised to inspect outbound connections, review repository logs, and rotate credentials. Additionally, enhancing privileged workflow security, particularly those involving pull_request_target, is crucial.

Indicators of compromise have been detailed, including specific npm package versions and network signatures. These indicators should be incorporated into monitoring strategies to detect and mitigate similar threats effectively.

The attack serves as a stark reminder of the vulnerabilities inherent in automation processes and the necessity of robust security measures to safeguard against sophisticated threats in software ecosystems.

Cyber Security News Tags:AsyncAPI, automation security, CI/CD pipelines, Cybersecurity, developer tools, GitHub, GitHub actions, JavaScript, Malware, Miasma RAT, Node.js, npm packages, Software Security, supply chain attack, Vulnerability

Post navigation

Previous Post: AI Safety Leadership in Flux as Director Resigns

Related Posts

Google Unveils AI Security Enhancements for Android Google Unveils AI Security Enhancements for Android Cyber Security News
AI Exploits Lead to Global FortiGate Cybersecurity Breach AI Exploits Lead to Global FortiGate Cybersecurity Breach Cyber Security News
Former GCHQ Intern Jailed for Seven Years After Copying Top Secret Files to Mobile Phone Former GCHQ Intern Jailed for Seven Years After Copying Top Secret Files to Mobile Phone Cyber Security News
Fake CERT-UA Website Distributes Go-Based Malware Fake CERT-UA Website Distributes Go-Based Malware Cyber Security News
Multiple GitLab Vulnerabilities Allow Attackers to Achieve Complete Account Takeover Multiple GitLab Vulnerabilities Allow Attackers to Achieve Complete Account Takeover Cyber Security News
Hackers Using Malicious Imageless QR Codes to Render Phishing Attack Via HTML Table Hackers Using Malicious Imageless QR Codes to Render Phishing Attack Via HTML Table Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark