Security & Threat Intelligence · 25.07.2026, 15:29 UTC
Miasma Returns: Leo Platform Compromise in npm
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | Sonatype ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
TL;DR The Shai-Hulud Miasma campaign has a fresh series of malicious packages following the compromise of the czirker maintainer account, affecting both the RStreams and Leo Platform ecosystems. Sonatype is implicating 23 malicious package versions with this campaign. This wave builds directly on the Miasma playbook Sonatype recently reported: moving beyond obvious preinstall and postinstall scripts to abuse binding.gyp, steal credentials, validate access, and propagate through trusted package publishing workflows. Organizations that installed affected versions should treat impacted developer workstations, CI/CD runners, build containers, and production-adjacent environments as potentially compromised. Remove malicious versions, investigate install-time execution, and rotate credentials only after persistence has been removed. How the Leo Platform npm Compromise Turned Trust Into Execution Attackers are not just publishing suspicious new packages and waiting for someone to typo their way into trouble. Increasingly, they are compromising the packages developers already trust. On June 25, 2026, industry researchers began reporting another npm supply chain compromise tied to the Shai-Hulud Miasma malicious package campaign. Early reporting pointed to a compromised maintainer account used to publish malicious versions of packages associated with the Leo Platform ecosystem. We have seen this pattern before: compromise a trusted maintainer or publishing workflow, modify legitimate packages, and let downstream automation do the rest. What makes this wave especially …