Security & Threat Intelligence · 25.07.2026, 15:29 UTC
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | Tenable Research ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
A stolen session cookie sat in underground markets for seven weeks before attackers used it to poison 32 Red Hat packages in the npm software registry, an example of the industrial approach behind modern supply chain attacks.Key takeawaysMiasma is a self-propagating npm worm derived from Mini Shai-Hulud that TeamPCP open-sourced on May 12. The public release of the full weaponized toolchain means any operator can now replicate structurally identical supply chain campaigns.The Miasma campaign compromised 89-plus npm packages across three waves (June 1-5), affecting Red Hat, Vapi.ai, and Microsoft Azure repositories. The worm produced malicious packages with valid SLSA Build Level 3 provenance attestations, defeating the highest tier of supply-chain integrity verification.The root cause was a stolen developer credential that sat in infostealer logs for seven weeks before weaponization. This infostealer-to-supply-chain pipeline is the defining pattern of the Developer Credential Economy.The Miasma campaign’s third wave (June 5) introduced a significant escalation: persistence files that target AI coding assistants (Claude Code, Cursor, Gemini CLI, VS Code), expanding the attack surface from package registries to the developer’s local environment.Relying on execution-layer detection, such as EDR, is insufficient against supply chain threats because EDR tools lack visibility into the ephemeral CI/CD environments where credential theft and weaponization occur.Organizations should treat developer credentials as control-plane infrastructure and adopt a phased Continuous Threat …