The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
Blog post from GitGuardian
Between June and July 14, 2026, a series of supply chain attacks targeted npm and PyPI, exploiting different entry points to harvest credentials from developer environments and build pipelines. The Miasma worm continued its spread from Red Hat to npm, while a new Rust-built infostealer, IronWorm, was discovered by JFrog, hidden behind an eBPF kernel rootkit to distribute trojanized packages. Subsequent attacks included a variant of Miasma on PyPI named Hades, which used a novel delivery mechanism to infect Python packages; a fake payment SDK operation that harvested CI secrets; a compromised npm token to distribute malicious versions of jscrambler; and an abuse of the pull_request_target workflow in AsyncAPI's CI pipeline to steal credentials. These incidents highlight vulnerabilities in package management systems and CI pipelines, emphasizing the need for improved security measures, such as disabling install scripts by default in npm v12 and adopting safer workflow defaults in actions/checkout v7. Despite these efforts, the attacks reveal that provenance and ecosystem guardrails have limitations, as they can verify the origin of packages but cannot ensure the safety of the code or determine the extent of credential exposure, underscoring the importance of preemptive visibility into secrets and configurations.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.