Campaign · Open Source · · 46 days

Miasma worm burrowed through npm for two months

Miasma was a 2026 npm worm that stole CI and cloud credentials, then republished trojanized versions from any maintainer account it reached. It ran from the @redhat-cloud-services compromise on May 29 through the AsyncAPI releases on July 14.

Draws together 4 incidents across 61 packages

A self-propagating npm worm that researchers named Miasma spent roughly seven weeks in the summer of 2026 moving from one maintainer account to the next, harvesting cloud and CI credentials and using them to publish poisoned versions of whatever packages it could reach. Red Hat, the AsyncAPI project, and the voice-AI vendor Vapi were among the names it burned through.

Miasma's first widely reported outing came on May 29, 2026, when an attacker used a Red Hat employee's GitHub account to inject a malicious preinstall script into packages in the @redhat-cloud-services npm namespace. Red Hat said the account had itself been compromised by a malicious VS Code extension, which is a reminder that the worm did not need to break npm to get npm publish rights.

Five days later the operators changed how the code fired. On June 3, StepSecurity documented a wave it called "Phantom Gyp," in which the payload abandoned preinstall and postinstall hooks entirely and instead hid execution inside a 157-byte binding.gyp file. Because node-gyp evaluates shell commands in that file during dependency installation, the code ran on npm install without ever appearing in a lifecycle-script scanner. Snyk counted 57 affected packages and more than 300 malicious versions.

The July 14 AsyncAPI compromise moved the trigger again, this time to module import. Socket said the loader fetched an 8.25 MB encrypted second stage from IPFS and unpacked a modular tasking framework with shell execution, file transfer, and systemd persistence. Across all three waves the objective stayed constant: credentials from developer laptops and build runners, exfiltrated to attacker-controlled GitHub repositories and then reinvested in the next round of publishing.

Notes

  • The three waves recorded here differ in execution trigger rather than in payload goal. May 29 used a preinstall script, June 3 used binding.gyp evaluation during node-gyp dependency installation, and July 14 used module import. Detection tooling that keyed on lifecycle scripts missed the second and third.
  • The 2026-06-24 wave recorded at [[leoplatform-rstreams]] carried the campaign outside npm for the first time, reaching a Verana Blockchain Go module. Researchers use Mini Shai-Hulud, Miasma, and Hades for overlapping parts of this family.
  • Miasma is distinct from the TeamPCP Mini Shai-Hulud lineage tracked under [[shai-hulud-here-we-go-again]], though both are credential-harvesting npm worms active in the same period and both abuse npm trusted publishing to self-propagate. No public source attributes them to the same operator.

Incidents in this campaign

  1. Red Hat npm namespace poisoned via a maintainer's editor
  2. Vapi server SDK caught in the Phantom Gyp npm wave
  3. Miasma poisoned LeoPlatform npm and jumped to a Go module
  4. AsyncAPI npm releases carried a Miasma botnet loader

Appendix · Affected packages

@redhat-cloud-services 2026-05-29 to 2026-06-02
3.6.13.6.23.6.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
7.4.17.4.27.4.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
7.7.27.7.37.7.5
@redhat-cloud-services 2026-05-29 to 2026-06-02
9.0.39.0.49.0.6
@redhat-cloud-services 2026-05-29 to 2026-06-02
2.0.82.0.92.0.11
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.11.24.11.34.11.5
@redhat-cloud-services 2026-05-29 to 2026-06-02
6.9.26.9.36.9.5
@redhat-cloud-services 2026-05-29 to 2026-06-02
1.2.21.2.41.2.6
@redhat-cloud-services 2026-05-29 to 2026-06-02
6.11.36.11.46.11.6
@redhat-cloud-services 2026-05-29 to 2026-06-02
3.2.13.2.23.2.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
5.0.35.0.45.0.6
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.7.24.7.34.7.5
49 more packages
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.9.24.9.34.9.5
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.4.14.4.24.4.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
2.1.82.1.92.1.11
@redhat-cloud-services 2026-05-29 to 2026-06-02
3.8.23.8.43.8.6
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.0.114.0.124.0.14
@redhat-cloud-services 2026-05-29 to 2026-06-02
2.3.12.3.22.3.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
6.1.46.1.56.1.7
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.0.34.0.44.0.6
@redhat-cloud-services 2026-05-29 to 2026-06-02
3.0.103.0.113.0.13
@redhat-cloud-services 2026-05-29 to 2026-06-02
6.0.46.0.56.0.7
@redhat-cloud-services 2026-05-29 to 2026-06-02
1.2.11.2.21.2.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.0.44.0.54.0.7
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.0.44.0.54.0.7
@redhat-cloud-services 2026-05-29 to 2026-06-02
3.0.103.0.113.0.13
@redhat-cloud-services 2026-05-29 to 2026-06-02
5.0.45.0.55.0.7
@redhat-cloud-services 2026-05-29 to 2026-06-02
0.6.10.6.20.6.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.0.114.0.124.0.14
@redhat-cloud-services 2026-05-29 to 2026-06-02
4.0.44.0.54.0.7
@redhat-cloud-services 2026-05-29 to 2026-06-02
0.3.10.3.20.3.4
@redhat-cloud-services 2026-05-29 to 2026-06-02
0.3.10.3.20.3.4
@vapi-ai 2026-06-03
0.11.10.11.21.2.1 +1 more
hexo-deployer-wrangler 2026-06-24 to 2026-06-26
1.0.4
hexo-shoka-swiper 2026-06-24 to 2026-06-26
0.1.10
leo-auth 2026-06-24 to 2026-06-26
4.0.6
leo-aws 2026-06-24 to 2026-06-26
2.0.4
leo-cache 2026-06-24 to 2026-06-26
1.0.2
leo-cdk-lib 2026-06-24 to 2026-06-26
0.0.2
leo-cli 2026-06-24 to 2026-06-26
3.0.3
leo-config 2026-06-24 to 2026-06-26
1.1.1
leo-connector-elasticsearch 2026-06-24 to 2026-06-26
2.0.6
leo-connector-mongo 2026-06-24 to 2026-06-26
3.0.8
leo-connector-mysql 2026-06-24 to 2026-06-26
3.0.3
leo-connector-oracle 2026-06-24 to 2026-06-26
2.0.1
leo-connector-redshift 2026-06-24 to 2026-06-26
3.0.6
leo-cron 2026-06-24 to 2026-06-26
2.0.2
leo-logger 2026-06-24 to 2026-06-26
1.0.8
leo-sdk 2026-06-24 to 2026-06-26
6.0.19
leo-streams 2026-06-24 to 2026-06-26
2.0.1
prism-silq 2026-06-24 to 2026-06-26
1.0.1
rstreams-metrics 2026-06-24 to 2026-06-26
2.0.2
rstreams-shard-util 2026-06-24 to 2026-06-26
1.0.1
serverless-convention 2026-06-24 to 2026-06-26
2.0.4
serverless-leo 2026-06-24 to 2026-06-26
3.0.14
solo-nav 2026-06-24 to 2026-06-26
1.0.1
github.com 2026-06-24 to 2026-06-26
v0.10.1-dev.20
@asyncapi 2026-07-14
1.1.1
@asyncapi 2026-07-14
0.7.1
@asyncapi 2026-07-14
3.3.1
@asyncapi 2026-07-14
6.11.26.11.2-alpha.1

Samples and hashes sit on each incident page, linked above

References

  1. RHSB-2026-006 Supply chain compromise of @redhat-cloud-services npm packages - Red Hataccess.redhat.com
  2. Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp - StepSecuritystepsecurity.io
  3. Node-gyp Supply Chain Compromise - Snyksnyk.io
  4. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader - Socketsocket.dev
  5. IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks - The Hacker Newsthehackernews.com

Source record: oss/campaigns/miasma-2026/meta.yaml