Miasma Campaign Exploits npm binding.gyp for CI/CD Theft
Score: 9/10

Miasma Campaign Exploits npm binding.gyp for CI/CD Theft

The Miasma threat actor compromised 56 npm packages to steal CI/CD secrets and deploy persistent backdoors using a novel binding.gyp execution trigger.

Executive Summary

In June 2026, a coordinated supply chain campaign dubbed 'Miasma - The Spreading Blight' published 286 malicious versions of 56 npm packages. The attack bypassed traditional security audits by utilizing the 'binding.gyp' native build file to trigger silent code execution during 'npm install', rather than standard lifecycle hooks. This campaign specifically targeted developer tooling and CI/CD environments to exfiltrate highly sensitive cloud and repository credentials.

Technically, the malware employed a multi-layered defense strategy, including AES-128-GCM encryption unique to each package version and anti-forensics that delete staging artifacts. Once active, the payload harvests environment variables for AWS, Azure, GCP, and GitHub, while installing persistent systemd or LaunchAgent services. Notably, the malware includes a 'dead man's switch' designed to wipe the user's home directory if compromised GitHub tokens are revoked before the infected machine is isolated.

This campaign represents a significant escalation in software supply chain tradecraft, impacting sectors reliant on modern JavaScript and TypeScript development. The breadth of the compromises suggests the attacker obtained high-level publishing credentials, potentially through shared infrastructure or organizational account breaches.

Key Details

Threat Name

Miasma - The Spreading Blight Campaign

Affects

—

Adversary

Miasma - The Spreading Blight

Malware/Tools

Miasma, update-monitor, gh-token-monitor

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance10
Clarity & Structure10
Technical Depth9

Sources