Post
CRITICAL ⚡ MUST-KNOW

Miasma Supply-Chain Malware Expands to npm, GitHub Actions, and Go

· supply-chain · npm · github · malware

Researchers have flagged Miasma, the latest evolution of a supply-chain attack lineage that includes Mini Shai-Hulud and Hades, now compromising a new set of npm packages while propagating to the Go ecosystem. The latest activity includes malicious npm releases affecting the LeoPlatform and RStreams packages, abuse of GitHub Actions workflows, and a related Go package compromise. The campaign continues to evolve across ecosystems rather than being contained to a single vendor or registry.