← Back to KHAO

Microsoft · GitHub · Google · Kubernetes ·

Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

2 min read

Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.

◌ Single Source

Two clenched fists collide in a dramatic illustration with sparks and a dark background.

Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers.

Key facts

Summary

The Miasma malware campaign has claimed another victim, poisoning more than 20 versions of legitimate npm packages used by the Leo Platform and RStreams ecosystems as its operators continue refining their self-propagating supply chain worm. Microsoft Threat Intelligence said in a post on X that the attack began late on June 24 after attackers compromised an npm maintainer account, "czirker," and used it to publish poisoned updates to more than 20 packages in a "coordinated, fully automated operation completed in under three seconds. Like earlier Miasma campaigns, the malware targets developer workstations and CI runners, hunting for AWS, Azure, and Google Cloud credentials alongside GitHub personal access tokens, Kubernetes secrets, HashiCorp Vault credentials, 1Password data, npm publishing credentials, and other sensitive information.

Read full article at The Register →

#Microsoft #GitHub #Google #Kubernetes