Threats · 80 days ago
The blast radius is the maintainer identity, not just the poisoned package. Once attackers control a real publisher account and CI secrets, they can keep pushing malicious artifacts through the same trusted release paths across registries and workflows.
Socket links the new wave to malicious npm releases in the LeoPlatform and RStreams families, a compromised Verana Blockchain Go module, and GitHub Actions abuse. It also points to a suspected breached npm maintainer account, 'czirker', that let the campaign spread with little manual effort and steal more developer credentials.
That makes cleanup harder than removing one bad version. If the same publishing or workflow credentials are still valid, the campaign can keep generating new malicious releases across npm, Go, and GitHub Actions.
3 sources covering this story
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Mini Shai-Hulud-linked malware compromises 23 npm packages and a Verana Go module to steal developer credentials.
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git...
Mini Shai-Hulud expands into the Go ecosystem after hitting LeoPlatform npm packages and targeting GitHub Actions workflows.
Part of the PlainSec briefing for 2026-06-27