1mo ago · socket-dev
A new wave of the Miasma Mini Shai-Hulud supply chain attack has compromised npm packages under LeoPlatform and RStreams, as well as a Go module associated with Verana Blockchain. The campaign uses malicious binding.gyp files in npm packages to trigger JavaScript execution during installation, stages payloads via Bun, and targets developer environments, CI/CD pipelines, and GitHub Actions for credential theft. It also spreads through poisoned repositories and source configurations, with persistence mechanisms targeting AI coding assistants and IDEs. The activity overlaps with prior incidents involving the same malware family and operational markers like 'RevokeAndItGoesKaboom'.