Miasma: supply‑chain attack compromises npm packages and GitHub Actions

Colleagues — cybersecurity alert: Miasma is targeting npm packages and GitHub Actions.
Researchers report trojanized releases for LeoPlatform packages and the Go module Verana. An npm account appears compromised; an npm token was used to rapidly publish malicious versions.
Attack vector: binding.gyp executes code at install time; attackers fetch Bun and run a stealer to exfiltrate tokens and secrets. They also harvest GitHub Actions secrets via workflows and publish stolen data to public repositories.
Why it matters: compromising developer workflows endangers CI/CD, repositories and downstream users.
How will you strengthen your supply‑chain defenses?
#cybersecurity #supplychain #DevSecOps #GitHubActions

