Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages

Blog post from Semgrep

Post Details
Company
Date Published
Author
Katie Paxton-Fear
Word Count
711
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

Miasma, a self-spreading npm worm, has compromised 57 npm packages through over 286 malicious versions, using an unconventional method involving a 157-byte binding.gyp file for code execution during npm install without lifecycle scripts. This malware rapidly spreads across npm packages, harvesting sensitive credentials from AWS, GCP, Azure, and GitHub Actions secrets, and exfiltrating them to attacker-controlled GitHub repositories. It further injects persistent backdoors into AI coding-assistant configuration files, poisoning AI-generated code and mimicking Mini Shai-Hulud by forging provenance attestations to appear legitimate. The attack necessitates urgent scans and credential rotations for affected systems, with indicators of compromise including specific exfiltration path patterns and C2 beacon keywords.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 3 7,668 844 209 +8%
AI Coding Assistant 1 2,161 541 167 +20%
Secrets Management 1 2,515 393 134 +17%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.