Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp
Blog post from Endor Labs
Endor Labs identified four malicious versions of the ai-sdk-ollama npm package, which acts as an unofficial bridge between Ollama and the Vercel AI SDK, published almost simultaneously, indicating a coordinated attack. These versions were part of the Miasma npm worm campaign, which exploits the binding.gyp file to execute a payload during installation, bypassing conventional security checks for lifecycle scripts. The payload employs layered obfuscation techniques and rotating keys to evade detection, with a multi-cloud credential-stealing final stage that collects AWS, GCP, Azure, and GitHub tokens, among others, and exhibits worm-like self-replicating behavior. The campaign involves republishing compromised versions across multiple accounts, potentially impacting a wide range of users. Users are advised to audit their dependency trees, rotate credentials, and adopt stricter security measures to mitigate future risks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 20 | 2,539 | 400 | 136 | +9% |
| Kubernetes | 6 | 2,083 | 321 | 111 | +3% |
| MCP | 3 | 7,755 | 862 | 214 | 0% |
| LLM | 1 | 6,292 | 1,205 | 252 | -36% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.