news.mlab.sh
Back to the feed
supply-chain

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

High
Image: The Hacker News
Summary

A sophisticated supply chain attack, spearheaded by the Miasma malware family (linked to Mini Shai-Hulud and Hades), is targeting npm packages and GitHub Actions workflows. The attackers are leveraging compromised npm packages, GitHub Actions secrets, and IDE persistence to steal developer credentials and propagate malicious code across package registries and repositories. This campaign highlights the ongoing threat of supply chain attacks and the need for robust security practices within developer workflows.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.