Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages
Blog post from Semgrep
Miasma, a self-spreading npm worm, has compromised 57 npm packages through over 286 malicious versions, using an unconventional method involving a 157-byte binding.gyp file for code execution during npm install without lifecycle scripts. This malware rapidly spreads across npm packages, harvesting sensitive credentials from AWS, GCP, Azure, and GitHub Actions secrets, and exfiltrating them to attacker-controlled GitHub repositories. It further injects persistent backdoors into AI coding-assistant configuration files, poisoning AI-generated code and mimicking Mini Shai-Hulud by forging provenance attestations to appear legitimate. The attack necessitates urgent scans and credential rotations for affected systems, with indicators of compromise including specific exfiltration path patterns and C2 beacon keywords.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 3 | 7,668 | 844 | 209 | +8% |
| AI Coding Assistant | 1 | 2,161 | 541 | 167 | +20% |
| Secrets Management | 1 | 2,515 | 393 | 134 | +17% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.