VMTech
Discuss a project

Miasma: supply‑chain attack compromises npm packages and GitHub Actions

Miasma: supply‑chain attack compromises npm packages and GitHub Actions

Colleagues — cybersecurity alert: Miasma is targeting npm packages and GitHub Actions.

Researchers report trojanized releases for LeoPlatform packages and the Go module Verana. An npm account appears compromised; an npm token was used to rapidly publish malicious versions.

Attack vector: binding.gyp executes code at install time; attackers fetch Bun and run a stealer to exfiltrate tokens and secrets. They also harvest GitHub Actions secrets via workflows and publish stolen data to public repositories.

Why it matters: compromising developer workflows endangers CI/CD, repositories and downstream users.

How will you strengthen your supply‑chain defenses?

#cybersecurity #supplychain #DevSecOps #GitHubActions

Open analytics
On the site 1 views
min read 1 28.06.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Miasma: supply‑chain attack compromises npm packages and GitHub Actions

Open the post on Instagram ↗