Malicious 'Miasma' Framework Compromises 32 Red Hat npm Packages in Supply Chain Attack
Toasted to a respectable shade. No regrets, no crumbs left.
Summary
A malicious open-source framework called 'Miasma' (a Shai-Hulud clone) compromised 32 Red Hat npm packages. GitHub removed the repository, but forks had already been created. The framework includes credential harvesting, supply chain poisoning, encrypted data exfiltration targeting developer workstations and CI/CD pipelines, persistence enhancements using AI agents, and Sigstore provenance theft. Researchers noted that open-sourcing this active campaign lowers adoption barriers for techniques like OIDC token abuse, provenance forgery, and AI tool persistence hooks.
Key quotes
· 3 pulledGitHub removed the repository soon after it appeared, but forks were already created.
The modular framework included credential harvesting, supply chain poisoning, and encrypted data exfiltration aimed at developer workstations and CI/CD pipelines.
Researchers noted the unusual open-sourcing of an active campaign lowers adoption barriers for techniques like OIDC token abuse, provenance forgery, and AI tool persistence hooks.
You might also wanna read
Multiple @redhat-cloud-services npm packages compromised in supply chain attack
Multiple npm packages under the @redhat-cloud-services scope have been compromised with malicious releases. The affected packages include @r
GitLab Identifies Large-Scale npm Supply Chain Attack with Destructive Malware
GitLab's security researchers have uncovered a large-scale supply chain attack in the npm ecosystem involving a destructive malware variant
Supply Chain Attacks on Open-Source Software: Case Study of Malicious Pull Request Attempts
The article discusses recent supply chain attacks on open-source software projects like LiteLLM and axios, with a specific case study of att
Shai-Hulud: Largest npm Supply-Chain Compromise Affecting CrowdStrike and Hundreds of Packages
The Shai-Hulud malware campaign represents the largest and most dangerous npm supply-chain compromise in history, affecting hundreds of pack
317 npm Packages Compromised in Mini Shai-Hulud Supply Chain Attack
A major npm supply chain attack occurred on May 19, 2026, when the npm account of maintainer "atool" was compromised. The attacker published
NPM supply chain attack compromises popular packages, posing widespread security risk
A significant supply chain attack on the NPM package ecosystem compromised several popular packages, potentially allowing malicious code to
