Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal
Word Count
2,907
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

A sophisticated supply chain attack is spreading through the npm registry by exploiting the binding.gyp file, which is usually overlooked by security tools, to execute attacker-controlled code during npm installs. This attack, tracked as the Node-gyp Supply Chain Compromise by Snyk, affects 57 packages with hundreds of malicious versions, classified as Critical severity due to embedded malicious code. The payload is designed to steal developer and CI/CD credentials from platforms like npm, GitHub, AWS, and others, exfiltrating them through GitHub repositories and injecting persistent workflows. The attack, named "Miasma" and linked to the Shai-Hulud worm family, uses a novel technique called "Phantom Gyp" to trigger code execution at install time, bypassing traditional lifecycle script checks. The campaign has primarily targeted packages from a small number of maintainer accounts, and the malicious versions remain available for installation, posing ongoing risks. To mitigate the threat, affected parties are advised to pin dependencies to known-good versions, use --ignore-scripts during npm installs, rotate credentials, and scan for malicious packages using tools like Snyk. This incident highlights the evolving nature of supply chain attacks, emphasizing the need for robust security practices to detect and remediate such threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 7 2,539 400 136 +9%
Kubernetes 3 2,083 321 111 +3%
AI Coding Assistant 2 2,234 577 171 +12%
MCP 2 7,755 862 214 0%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.