A new wave of the Mini Shai-Hulud/Miasma/Hades supply chain attack campaign has compromised 23 npm packages across the LeoPlatform and RStreams ecosystems, plus the Verana Blockchain Go module. The attack uses binding.gyp install-time execution (Phantom Gyp pattern) to trigger multi-stage obfuscated JavaScript loaders that decrypt AES-GCM payloads, stage execution through Bun to evade Node.js security hooks, and steal developer/CI/CD credentials including npm, GitHub, cloud, and AI-agent tokens. The campaign also poisons GitHub Actions workflows and plants persistence hooks in AI coding assistant configurations, creating delayed execution surfaces that survive package remediation.
npm malware
2 posts
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem Socket Named a Supply Chain Innovator in Latio's 2026 Application Security Market Report Latio's 2026 Application Security Market Report highlights supply chain malware and the securing of AI-generated code as the top security concerns for practitioners. The report emphasizes the inadequacy of traditional CVE scanning, citing the multi-wave Shai Hulud campaign—which compromised over 500 npm packages, exposed GitHub secrets, and targeted AI toolchains—as evidence that proactive dependency analysis is essential.