Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
Blog post from Snyk
A sophisticated supply chain attack is spreading through the npm registry by exploiting the binding.gyp file, which is usually overlooked by security tools, to execute attacker-controlled code during npm installs. This attack, tracked as the Node-gyp Supply Chain Compromise by Snyk, affects 57 packages with hundreds of malicious versions, classified as Critical severity due to embedded malicious code. The payload is designed to steal developer and CI/CD credentials from platforms like npm, GitHub, AWS, and others, exfiltrating them through GitHub repositories and injecting persistent workflows. The attack, named "Miasma" and linked to the Shai-Hulud worm family, uses a novel technique called "Phantom Gyp" to trigger code execution at install time, bypassing traditional lifecycle script checks. The campaign has primarily targeted packages from a small number of maintainer accounts, and the malicious versions remain available for installation, posing ongoing risks. To mitigate the threat, affected parties are advised to pin dependencies to known-good versions, use --ignore-scripts during npm installs, rotate credentials, and scan for malicious packages using tools like Snyk. This incident highlights the evolving nature of supply chain attacks, emphasizing the need for robust security practices to detect and remediate such threats.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 7 | 2,539 | 400 | 136 | +9% |
| Kubernetes | 3 | 2,083 | 321 | 111 | +3% |
| AI Coding Assistant | 2 | 2,234 | 577 | 171 | +12% |
| MCP | 2 | 7,755 | 862 | 214 | 0% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.