Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp
Blog post from Endor Labs
Endor Labs identified four malicious versions of the ai-sdk-ollama npm package, which acts as an unofficial bridge between Ollama and the Vercel AI SDK, published almost simultaneously, indicating a coordinated attack. These versions were part of the Miasma npm worm campaign, which exploits the binding.gyp file to execute a payload during installation, bypassing conventional security checks for lifecycle scripts. The payload employs layered obfuscation techniques and rotating keys to evade detection, with a multi-cloud credential-stealing final stage that collects AWS, GCP, Azure, and GitHub tokens, among others, and exhibits worm-like self-replicating behavior. The campaign involves republishing compromised versions across multiple accounts, potentially impacting a wide range of users. Users are advised to audit their dependency trees, rotate credentials, and adopt stricter security measures to mitigate future risks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 20 | 2,515 | 393 | 134 | +17% |
| Kubernetes | 6 | 2,168 | 322 | 107 | +10% |
| MCP | 3 | 7,668 | 844 | 209 | +8% |
| LLM | 1 | 6,237 | 1,165 | 246 | -31% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.