Skip to main content
AVOID.NET

node-gyp npm Supply Chain Compromise (June 2026)

avoid.net/node-gyp-npm-supply-chain-compromise-june-20260/100·93% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4e6zEu…MqY3

Summary

In June 2026, a self-propagating npm supply chain worm designated 'Miasma' exploited a novel install-time execution technique called 'Phantom Gyp' — abusing binding.gyp configuration files to trigger malicious code during npm install. The campaign spread across 57 packages and 286+ malicious versions, harvesting developer and CI/CD credentials from npm, GitHub, AWS, GCP, Azure, HashiCorp Vault, and Kubernetes, and then self-propagating by republishing poisoned releases using stolen publishing tokens. The attack poses a direct threat to crypto developers whose CI/CD pipelines manage private keys, wallet seed phrases, and signing infrastructure.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about node-gyp npm Supply Chain Compromise (June 2026)?

Timeline(6 events)

June 2026

Wave 1: Attacker uses a compromised Red Hat employee GitHub account to inject malicious preinstall hooks into 32+ packages (96 versions) across the @redhat-cloud-services npm namespace; Wiz Research identifies the compromise; most malicious versions revoked by 14:00 UTC.

Wiz Blog / JFrog Security Research

3 June 2026

Wave 2 begins at 23:30 UTC: four malicious versions of @vapi-ai/server-sdk published using the Phantom Gyp (binding.gyp) technique; within under two hours, 50+ additional packages in the jagreehal maintainer account and related families are compromised — 57 packages and 286+ malicious versions in total.

StepSecurity / Snyk

4 June 2026

StepSecurity publishes initial disclosure naming the technique 'Phantom Gyp' and the campaign 'Miasma'; JFrog publishes analysis tying it to the Shai-Hulud worm lineage; malicious Wave 2 package versions begin to be delisted from the npm registry.

StepSecurity / JFrog Security Research

5 June 2026

Snyk, ReversingLabs, Corgea, Chainguard, and Wiz publish independent technical analyses; Cybersecurity Dive reports on the Red Hat connection; Red Hat confirms no official products were impacted.

Cybersecurity Dive

6 June 2026

JFrog identifies a 'Hades' variant of the campaign extending propagation to PyPI (.pth loader injection), RubyGems (extconf.rb injection), and JFrog Artifactory, and introducing AI assistant prompt injection via jailbreak prompts in Cursor, Copilot, and Claude rule files.

JFrog Security Research

13 June 2026

npm announces v12 security overhaul that will block install scripts (including binding.gyp-triggered node-gyp invocations) by default, with a July 2026 migration deadline for CI environments.

TechTimes
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 13 of 13 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 6/19/2026, 12:17:02 PM

last updated: 8/25/2026, 12:55:30 PM

4 views

avoid.net — verified advice for a post-truth world