CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Miasma Malware: Multi-Stage Botnet Loader with Advanced C2 Capabilities

June 26, 2026

Miasma is a multi-stage botnet loader identified in compromised AsyncAPI npm packages. It features a tasking framework with 744 modules, supporting six independent C2 channels including HTTP, Nostr relay, IPFS, BitTorrent DHT, libp2p GossipSub P2P mesh, and Ethereum smart contract. Miasma facilitates credential theft, AI tool poisoning, LAN lateral movement, and worm-like propagation across npm, PyPI, and Cargo registries. It includes persistence mechanisms for systemd, crontab, macOS launchd, and Windows Registry, and a dead man's switch that triggers a directory wipe if a stolen token is revoked. It avoids sandboxes, virtual environments, Russian language systems, and systems with security tools from CrowdStrike, SentinelOne, Microsoft Defender, CarbonBlack, Cylance, Osquery, Tanium, and Qualys.