Minacce · 95 giorni fa
Il punto non è un singolo pacchetto avvelenato. Quando un account maintainer reale e i secret dei workflow vengono rubati, la supply chain diventa un canale di propagazione quasi automatico tra registry, Go modules e GitHub Actions, e il controllo dei soli artefatti pubblicati non basta più.
Socket e The Hacker News confermano la nuova ondata su LeoPlatform e RStreams su npm, sul modulo Go di Verana Blockchain e su workflow di GitHub Actions. La campagna è legata a Miasma / Mini Shai-Hulud; gli indizi puntano a un account npm di LeoPlatform, 'czirker', compromesso e usato per spingere versioni trojanizzate in pochi secondi.
Per i team che pubblicano dipendenze JavaScript o Go, il rischio è l'identità di rilascio: gli stessi secret rubati possono generare nuovi artefatti malevoli oltre il pacchetto già individuato. In questo schema, rimuovere una release non chiude l'incidente se restano validi account, token e automazioni di build.
3 fonti che coprono questa storia
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Mini Shai-Hulud-linked malware compromises 23 npm packages and a Verana Go module to steal developer credentials.
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git...
Mini Shai-Hulud expands into the Go ecosystem after hitting LeoPlatform npm packages and targeting GitHub Actions workflows.
Part of the PlainSec briefing for 2026-06-27