CRITICAL ⚡ MUST-KNOW
Miasma Supply-Chain Malware Expands to npm, GitHub Actions, and Go
Researchers have flagged Miasma, the latest evolution of a supply-chain attack lineage that includes Mini Shai-Hulud and Hades, now compromising a new set of npm packages while propagating to the Go ecosystem. The latest activity includes malicious npm releases affecting the LeoPlatform and RStreams packages, abuse of GitHub Actions workflows, and a related Go package compromise. The campaign continues to evolve across ecosystems rather than being contained to a single vendor or registry.