Leo Platform npm Supply Chain Attack (June 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2yxVKS…DPG6Summary
On June 24, 2026, 20 npm packages belonging to the Leo Platform (LeoPlatform/LeoInsights) ecosystem were simultaneously compromised via a single hijacked maintainer account, delivering a credential-stealing worm structurally identical to the earlier Miasma campaign. The attack is attributed to tooling derived from the TeamPCP Shai-Hulud worm framework, which was open-sourced on May 12, 2026, enabling copycat or original-actor operations against new ecosystems. Approximately 13,600 weekly downloads were exposed to a payload capable of stealing CI/CD secrets, cloud credentials, cryptocurrency wallet files, and AI coding-tool configurations.
Connected Entities
4 entities · 55 linked investigations- Leo Platform npm Supply Chain Attack (June 2026)→mentioned with→Phantom Wallet(70%)
- Leo Platform npm Supply Chain Attack (June 2026)→mentioned with→Shai-Hulud / TeamPCP Supply Chain Attack(70%)
- Leo Platform npm Supply Chain Attack (June 2026)→mentioned with→UNUS SED LEO(70%)
Connected Through
3 shared actors · 55 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- □Phantom Walletorganizationalso inMastra AI npm Supply Chain Attack (June 2026)·0node-gyp npm Supply Chain Compromise (June 2026)·0Uniswap Google Ad Phishing Campaign (May 2026)·0UNK_DeadDrop North Korea Developer Phishing Campaign·0Miasma npm Supply Chain Attack (Red Hat)·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign·0Fake Jupiter CJUP Airdrop Phishing Campaign·0TeamPCP / Mini Shai-Hulud npm Supply Chain Worm·0Sector Drainer — DaaS Wallet Drainer with Phantom 0-Day Bypass·0Fake Uniswap V4 Airdrop Phishing Network (2026)·0Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)·0easy-day-js / Mastra npm Supply Chain Attack·0Phantom Gyp npm Supply Chain Attack (June 2026)·0Rugproof (Solana Launchpad)·0Fake MetaMask Update Phishing Campaign (May 2026)·0Cryptomus / Xeltox Enterprises Ltd.·0Quark Drainer·0GSD Cloud / Lex Christopherson·0AsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026·0Solidity Pro VSCode Extension (Malicious)·0CastleLoader / NeedleStealer Crypto Wallet Malware Campaign·0Morocoin / Berge Blockchain / Cirkor·0Donald G. Basile / Bitcoin Latinum (LTNM)·2Donald Basile / Bitcoin Latinum (LTNM) / Monsoon Blockchain Corporation·2Rublevka Team·2Miasma npm Supply Chain Attack·5DeepSnitch AI·12WAYGU CASH·18Ctrl Wallet — Security Exploit and Forced Shutdown·22BullX·27LiFi Finance·32Grass·38LiFi Protocol·38Leap Wallet·52Fuse Wallet·54Lulo·55Transak·55Famous Fox Federation·57Phantom Wallet·63Kaspa·64Dialect·69Glow Wallet·72
- □Shai-Hulud / TeamPCP Supply Chain Attackorganizationalso inShai-Hulud / TeamPCP Supply Chain Attack·0Phantom Gyp npm Supply Chain Attack (June 2026)·0AsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026·0ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvester·0keyv / cacheable npm Supply Chain Attack — TeamPCP Mini Shai-Hulud (August 2026)·0IronWorm npm Supply Chain Attack·0Miasma npm Supply Chain Attack (Red Hat)·0ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)·0TanStack npm Supply Chain Attack (Mini Shai-Hulud / TeamPCP)·0EVM Cross-Chain Wallet-Drain Campaign (June 2026)·0node-gyp npm Supply Chain Compromise (June 2026)·0TeamPCP / Mini Shai-Hulud npm Supply Chain Worm·0Miasma RedHat npm Supply Chain Attack·2Miasma npm Supply Chain Attack·5Trust Wallet Chrome Extension Hack (December 2025)·28
- □UNUS SED LEOorganization
Timeline(9 events)
2025
TeamPCP begins active supply chain attack campaigns targeting npm and PyPI ecosystems using the Shai-Hulud worm framework (approximate start based on reporting).
Datadog Security Labs13 April 2026
Credentials belonging to a Red Hat employee appear in commercial infostealer logs — the earliest known precursor to the subsequent Miasma campaign.
Microsoft Security Blog12 May 2026
TeamPCP open-sources the Shai-Hulud worm framework on GitHub under MIT License with the message 'Shai-Hulud: Open Sourcing The Carnage,' enabling potential copycat operations.
Datadog Security LabsJune 2026
Miasma first wave: malicious commits pushed to three @redhat-cloud-services repositories at 10:53 UTC.
Wiz Blog3 June 2026
Miasma campaign publicly confirmed: 32 @redhat-cloud-services npm packages compromised across 57 packages and 286 malicious versions using the Phantom Gyp technique.
Miasma Supply Chain Attack - The Hacker News5 June 2026
IronWorm campaign disclosed: 50+ npm packages trojanized via compromised 'asteroiddao' npm account, including Exodus cryptocurrency wallet file theft.
The Hacker News24 June 2026
Orphan branches created on Leo Platform GitHub repositories at approximately 22:50 UTC, containing weaponized Dependabot workflow files requesting OIDC publishing permissions.
SafeDep24 June 2026
At 23:04:55 UTC, 20 malicious npm package versions published across the Leo Platform ecosystem in a 3-second burst using the compromised czirker maintainer account.
StepSecurity25 June 2026
Public disclosure by StepSecurity and SafeDep; GBHackers reports attack as Shai-Hulud Hades Payload targeting Leo/RStreams packages.
GBHackersDecision Log
- hash: GM3BvCBEaBtWT2BEnYjibxKJMBiC1D4gPWrRCWq9nZgQ
This investigation is cryptographically anchored to the Solana blockchain (1 event). 14 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/25/2026, 5:03:56 PM
last updated: 7/27/2026, 10:56:29 AM
3 viewsavoid.net — verified advice for a post-truth world