Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Miasma Malware Targets npm and GitHub in New Attack

Miasma Malware Targets npm and GitHub in New Attack

Posted on June 26, 2026 By CWS

In a concerning development, cybersecurity experts have identified a new surge of supply chain attacks involving the notorious Miasma malware family. This latest threat has infiltrated npm packages and extended its reach to the Go ecosystem, raising alarms among developers and security professionals worldwide.

Scope of the Attack

The recent campaign features malicious npm releases impacting packages like LeoPlatform and RStreams, as well as GitHub Actions workflow exploits. A compromised Go module associated with the Verana Blockchain project has also been detected, illustrating the attack’s broad impact.

The primary objective remains consistent: to steal developer credentials and utilize the compromised data to infiltrate package registries, repositories, and trusted development processes. This poses a significant risk to the integrity of software development pipelines.

Details of Affected Packages

The list of compromised npm packages is extensive, including notable names such as hexo-deployer-wrangler, leo-auth, leo-aws, and serverless-leo, among others. Additionally, a Go module from the Verana Blockchain project is implicated, signifying the malware’s expansion beyond npm.

Security analysts suspect the breach of an npm developer account linked to LeoPlatform, possibly through credential leaks, enabling attackers to deploy trojanized package versions within seconds.

Miasma’s Malicious Techniques

This attack wave employs tactics seen in previous campaigns, such as npm registry poisoning and GitHub infrastructure manipulation. Notably, the malware omits a lifecycle hook in package.json, opting instead to execute arbitrary code via a binding.gyp file during installation.

The payload deploys a JavaScript loader to download and execute the Bun runtime, subsequently extracting sensitive data like secrets and tokens. The malware includes a Russian locale killswitch and circumvents endpoint security software. Furthermore, it creates a “Run Copilot” workflow to exfiltrate CI/CD secrets from memory, uploading them to a public GitHub repository.

Conclusion and Future Implications

This attack highlights the persistent threat posed by the Miasma malware family. By targeting developer workflows and leveraging minor variations to evade detection, the attackers continue to exploit legitimate package ecosystems.

As this campaign extends to the Verana GitHub repository, it underscores the critical need for vigilant security practices across all stages of software development. Developers and organizations must remain proactive in safeguarding their environments against evolving threats.

The Hacker News Tags:CI/CD security, Cybersecurity, developer credentials, developer security, GitHub actions, GitHub security, Go ecosystem, LeoPlatform, malicious packages, Malware, Miasma malware, npm attack, software vulnerabilities, supply chain attack, supply chain risk

Post navigation

Previous Post: Python.org Flaw Exposed Admin API Access Risks
Next Post: Linux Foundation Launches Akrites for Open Source Security

Related Posts

CloudZ Malware Exploits Phone Link for Credential Theft CloudZ Malware Exploits Phone Link for Credential Theft The Hacker News
Malicious Chrome Extensions Target Google and Telegram Data Malicious Chrome Extensions Target Google and Telegram Data The Hacker News
DPRK Cyber Attacks Exploit AI and npm Malware DPRK Cyber Attacks Exploit AI and npm Malware The Hacker News
Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats The Hacker News
Can Your Security Stack See ChatGPT? Why Network Visibility Matters Can Your Security Stack See ChatGPT? Why Network Visibility Matters The Hacker News
Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Nebulock Secures $25M for Advanced AI Security
  • New Linux Kernel Flaw DirtyClone Allows Root Access
  • Hackers Exploit Shopify’s Shop App with Phony Invoices
  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Nebulock Secures $25M for Advanced AI Security
  • New Linux Kernel Flaw DirtyClone Allows Root Access
  • Hackers Exploit Shopify’s Shop App with Phony Invoices
  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark