Malware · 118 giorni fa
La rottura è che il controllo dei package che cerca solo gli npm lifecycle scripts può essere ingannato. Miasma v2 fa eseguire codice durante l’installazione tramite un piccolo file binding.gyp malevolo, così un package può sembrare privo di script e comunque eseguire un worm.
3 fonti che coprono questa storia
Node-gyp Supply Chain Compromise | Snyk
A self-propagating npm worm uses binding.gyp and node-gyp to run code at install time, steal secrets, persist in GitHub, and spread through packages.
Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages
But with a switch from install scripts to binding.gyp, this latest wave has swept up 57 packages across 286+ malicious versions.
Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog
Detect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware.
Part of the PlainSec briefing for 2026-06-04