All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Malicious 'Miasma' Framework Compromises 32 Red Hat npm Packages in Supply Chain Attack

3d ago· 2 min readenNews

Summary

A malicious open-source framework called 'Miasma' (a Shai-Hulud clone) compromised 32 Red Hat npm packages. GitHub removed the repository, but forks had already been created. The framework includes credential harvesting, supply chain poisoning, encrypted data exfiltration targeting developer workstations and CI/CD pipelines, persistence enhancements using AI agents, and Sigstore provenance theft. Researchers noted that open-sourcing this active campaign lowers adoption barriers for techniques like OIDC token abuse, provenance forgery, and AI tool persistence hooks.

Key quotes

· 3 pulled
GitHub removed the repository soon after it appeared, but forks were already created.
The modular framework included credential harvesting, supply chain poisoning, and encrypted data exfiltration aimed at developer workstations and CI/CD pipelines.
Researchers noted the unusual open-sourcing of an active campaign lowers adoption barriers for techniques like OIDC token abuse, provenance forgery, and AI tool persistence hooks.
Snippet from the RSS feed
TeamPCP released Mini Shai-Hulud malware source code on GitHub, enabling rapid creation of variants targeting developer workstations and CI/CD pipelines.

You might also wanna read