Miasma worm is a new variant of Shai-Hulud
Blog post from Cloudsmith
Miasma, a self-replicating malware campaign, has recently disrupted the open-source software ecosystem, initially exploiting Red Hat's npm packages and spreading to 73 Microsoft GitHub repositories, including those related to Microsoft Azure and Durable Task. This worm, an evolved variant of the Mini Shai-Hulud by TeamPCP, highlights the vulnerabilities in the software supply chain, especially when relying on public registries and AI coding tools. Miasma cleverly exploits legitimate workflows and uses valid SLSA provenance attestations, making it indistinguishable from routine updates to conventional scanners. By compromising developer credentials, it targets both package registries and source repositories, aiming to harvest cloud identities and credentials from infected systems. Security experts recommend rotating credentials, auditing environments, and implementing explicit dependency allowlisting and strict Software Bill of Materials (SBOMs) to mitigate such threats. The campaign underscores the need for robust security measures like artifact management layers to block malicious packages, as evidenced by the open-sourcing of Miasma and its continued evolution, which now includes targeting bioinformatics tools and AI-specific packages.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 3 | 2,234 | 577 | 171 | +12% |
| Secrets Management | 3 | 2,539 | 400 | 136 | +9% |
| MCP | 2 | 7,755 | 862 | 214 | 0% |
| Real-time | 1 | 6,055 | 1,444 | 270 | -11% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.