Miasma RedHat npm Supply Chain Attack
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5ihgTR…oJDTSummary
Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.
Connected Entities
1 entities · 10 linked investigations- + 2 more
Timeline(13 events)
13 April 2026
Red Hat employee GitHub credentials appear in infostealer logs, approximately 7 weeks before weaponization.
Cloud Security Alliance Research Note; Wiz Blog22 April 2026
Bitwarden CLI compromised via poisoned GitHub Actions workflow in the Mini Shai-Hulud campaign; payload targets crypto wallet data.
Aikido Security; The Hacker News29 April 2026
Four SAP npm packages compromised via leaked npm token in the Mini Shai-Hulud campaign.
Aikido Security30 April 2026
PyTorch Lightning package compromised on PyPI as part of the same campaign.
Aikido Security12 May 2026
TeamPCP open-sources the full Mini Shai-Hulud worm source code on GitHub under MIT License; simultaneously announces a $1,000 BreachForums contest for the largest supply chain attack using the code. Concurrently, the campaign expands to 160+ packages.
ReversingLabs; Tenable; Security Boulevard19 May 2026
Microsoft's DurableTask npm package compromised in the Mini Shai-Hulud campaign.
Aikido Security20 May 2026
Nine malicious Polymarket-branded npm packages published targeting crypto wallet keys.
SafeDep24 May 2026
Socket reports TrapDoor campaign: 34+ malicious packages across npm, PyPI, and Crates.io targeting crypto and DeFi developers.
CyberLeveling29 May 2026
First commit containing the 'Miasma: The Spreading Blight' string appears in RedHatInsights repositories.
The Hacker NewsJune 2026
Miasma attack executes in two waves (10:53 UTC and 13:44–13:46 UTC). Malicious commits pushed to RedHatInsights GitHub organization; 96 backdoored versions of 32 @redhat-cloud-services npm packages published with valid SLSA provenance attestations.
Wiz Blog; Orca Security; The RegisterJune 2026
Wiz Research publicly discloses the Miasma campaign. Red Hat removes affected packages from the npm registry and issues a statement that malicious code did not reach customer production systems.
The Register; BleepingComputer3 June 2026
Cloud Security Alliance publishes research note on Miasma with extended technical analysis.
Cloud Security AllianceDecision Log
- hash: 67ENERwMvWejE12hHanefbp6qe6cCFenewhZEToqvTA9
This investigation is cryptographically anchored to the Solana blockchain (1 event). 25 of 25 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/15/2026, 5:42:54 PM
last updated: 8/15/2026, 4:52:42 AM
3 viewsavoid.net — verified advice for a post-truth world