PulseAugur
EN
LIVE 07:35:42

Miasma malware poisons npm packages, targets developer secrets

A sophisticated malware campaign dubbed Miasma has compromised over 20 npm packages, targeting developers by stealing credentials and seeking to expand its reach. The attack specifically affected the Leo Platform and RStreams packages, with attackers aiming to gain access to more maintainers' accounts. Microsoft has been tracking this campaign, highlighting the growing threat to software supply chains. AI

IMPACT This incident highlights the increasing sophistication of supply chain attacks, posing a risk to AI development tools and infrastructure.

RANK_REASON The cluster describes a malware campaign targeting a software package registry, which falls under the category of tools and security threats.

Read on The Register — AI →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Miasma malware poisons npm packages, targets developer secrets

COVERAGE [2]

  1. The Register — AI TIER_1 English(EN) ·

    Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

    Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 Miasma campaign poisons 20-plus npm packages, hunts for developer secrets 📝 The Miasma malware campaign has ... https://www. theregister.com/security/2026/ 06

    🤖 Miasma campaign poisons 20-plus npm packages, hunts for developer secrets 📝 The Miasma malware campaign has ... https://www. theregister.com/security/2026/ 06/26/miasma-campaign-poisons-20-plus-npm-packages-hunts-for-developer-secrets/5262886 📰 www.theregister.com - Articles # …