Skip to main content
AVOID.NET

Leo Platform npm Supply Chain Attack (June 2026)

avoid.net/leo-platform-npm-supply-chain-attack-june-20263/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2yxVKS…DPG6

Summary

On June 24, 2026, 20 npm packages belonging to the Leo Platform (LeoPlatform/LeoInsights) ecosystem were simultaneously compromised via a single hijacked maintainer account, delivering a credential-stealing worm structurally identical to the earlier Miasma campaign. The attack is attributed to tooling derived from the TeamPCP Shai-Hulud worm framework, which was open-sourced on May 12, 2026, enabling copycat or original-actor operations against new ecosystems. Approximately 13,600 weekly downloads were exposed to a payload capable of stealing CI/CD secrets, cloud credentials, cryptocurrency wallet files, and AI coding-tool configurations.

Connected Entities

4 entities · 55 linked investigations
Organizations
Relationships
  • Leo Platform npm Supply Chain Attack (June 2026)mentioned withPhantom Wallet(70%)
  • Leo Platform npm Supply Chain Attack (June 2026)mentioned withShai-Hulud / TeamPCP Supply Chain Attack(70%)
  • Leo Platform npm Supply Chain Attack (June 2026)mentioned withUNUS SED LEO(70%)

Connected Through

3 shared actors · 55 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Leo Platform npm Supply Chain Attack (June 2026)?

Timeline(9 events)

2025

TeamPCP begins active supply chain attack campaigns targeting npm and PyPI ecosystems using the Shai-Hulud worm framework (approximate start based on reporting).

Datadog Security Labs

13 April 2026

Credentials belonging to a Red Hat employee appear in commercial infostealer logs — the earliest known precursor to the subsequent Miasma campaign.

Microsoft Security Blog

12 May 2026

TeamPCP open-sources the Shai-Hulud worm framework on GitHub under MIT License with the message 'Shai-Hulud: Open Sourcing The Carnage,' enabling potential copycat operations.

Datadog Security Labs

June 2026

Miasma first wave: malicious commits pushed to three @redhat-cloud-services repositories at 10:53 UTC.

Wiz Blog

3 June 2026

Miasma campaign publicly confirmed: 32 @redhat-cloud-services npm packages compromised across 57 packages and 286 malicious versions using the Phantom Gyp technique.

Miasma Supply Chain Attack - The Hacker News

5 June 2026

IronWorm campaign disclosed: 50+ npm packages trojanized via compromised 'asteroiddao' npm account, including Exodus cryptocurrency wallet file theft.

The Hacker News

24 June 2026

Orphan branches created on Leo Platform GitHub repositories at approximately 22:50 UTC, containing weaponized Dependabot workflow files requesting OIDC publishing permissions.

SafeDep

24 June 2026

At 23:04:55 UTC, 20 malicious npm package versions published across the Leo Platform ecosystem in a 3-second burst using the compromised czirker maintainer account.

StepSecurity

25 June 2026

Public disclosure by StepSecurity and SafeDep; GBHackers reports attack as Shai-Hulud Hades Payload targeting Leo/RStreams packages.

GBHackers
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 14 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 6/25/2026, 5:03:56 PM

last updated: 7/27/2026, 10:56:29 AM

3 views

avoid.net — verified advice for a post-truth world