CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

June 26, 2026

Cybersecurity researchers have flagged a new evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family, compromising a new set of npm packages and propagating to the Go ecosystem. The campaign aims to harvest developer or maintainer credentials and weaponize stolen data to spread across package registries, repositories, and trusted developer workflows.

Affected packages include hexo-deployer-wrangler, hexo-shoka-swiper, leo-auth, leo-aws, leo-cache, leo-cdk-lib, leo-cli, leo-config, leo-connector-elasticsearch, leo-connector-mongo, leo-connector-mysql, leo-connector-oracle, leo-connector-redshift, leo-cron, leo-logger, leo-sdk, leo-streams, prism-silq, rstreams-metrics, rstreams-shard-util, serverless-convention, serverless-leo, solo-nav, and the Go module github.com/verana-labs/verana-blockchain. An npm developer account associated with LeoPlatform (“czirker”) was likely breached via leaked credentials, allowing threat actors to push trojanized versions within a six-second window.

The attack employs tactics including npm registry poisoning, binding.gyp install-time execution, Bun-staged JavaScript malware, GitHub dead-drop infrastructure, GitHub Actions secret theft, IDE and AI coding assistant persistence, and encrypted credential exfiltration. Malicious npm packages use a binding.gyp file to execute arbitrary code during installation, launching a JavaScript loader that downloads the Bun runtime and initiates a stealer payload. The malware features a Russian locale killswitch, checks for endpoint security software, and drops a workflow named “Run Copilot” to capture CI/CD environment secrets, uploading them to a public GitHub repository with description “Alright Lets See If This Works.”

The token relay marker has changed from “IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner” to “RevokeAndItGoesKaboom.” On June 24, 2026, an attacker force-pushed a malicious commit to codfish/semantic-release-action, redirecting version tags to execute payloads that steal GitHub OIDC tokens and Personal Access Tokens. The malware also polls GitHub hourly for commits matching “firedalazer” to retrieve and execute the Hades variant. The Leo/RStreams package set is tied to cloud-native and serverless workloads, exposing developer workstations, CI/CD systems, AWS-backed applications, and downstream consumers. The poisoning of the Verana GitHub repository expands the campaign beyond npm, using the same Miasma execution pattern without relying on native Go module resolution.

CVEs: CVE-2026-11645

Malware: Miasma, Mini Shai-Hulud, Hades

Companies: Socket, StepSecurity, Endor Labs, OX Security, JFrog