Home / Companies / Cloudsmith / Blog / Post Details
Content Deep Dive

Miasma worm is a new variant of Shai-Hulud

Blog post from Cloudsmith

Post Details
Company
Date Published
Author
Nigel Douglas
Word Count
1,405
Company Posts That Month
12
Language
English
Hacker News Points
-
Post removed?
No
Summary

Miasma, a self-replicating malware campaign, has recently disrupted the open-source software ecosystem, initially exploiting Red Hat's npm packages and spreading to 73 Microsoft GitHub repositories, including those related to Microsoft Azure and Durable Task. This worm, an evolved variant of the Mini Shai-Hulud by TeamPCP, highlights the vulnerabilities in the software supply chain, especially when relying on public registries and AI coding tools. Miasma cleverly exploits legitimate workflows and uses valid SLSA provenance attestations, making it indistinguishable from routine updates to conventional scanners. By compromising developer credentials, it targets both package registries and source repositories, aiming to harvest cloud identities and credentials from infected systems. Security experts recommend rotating credentials, auditing environments, and implementing explicit dependency allowlisting and strict Software Bill of Materials (SBOMs) to mitigate such threats. The campaign underscores the need for robust security measures like artifact management layers to block malicious packages, as evidenced by the open-sourcing of Miasma and its continued evolution, which now includes targeting bioinformatics tools and AI-specific packages.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 3 2,234 577 171 +12%
Secrets Management 3 2,539 400 136 +9%
MCP 2 7,755 862 214 0%
Real-time 1 6,055 1,444 270 -11%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.