Miasma Malware Uses Phantom Gyp Technique to Target AI-Related npm Packages
Miasma is self-propagating malware that targets software supply chains and developer credentials. On June 1, 2026, it first breached Red Hat's @redhat-cloud-services namespace and compromised 32 packages within 72 seconds. The incident shows that AI development tools, cloud credentials and CI/CD environments have become key entry points for attackers seeking to spread malware and steal data.
On June 3, Miasma used a technique called “Phantom Gyp” to conceal commands in a 157-byte binding.gyp file, evading scans of package.json scripts. Within one hour, it compromised 57 npm packages and more than 286 versions, including Vapi's voice AI SDK, which has 408,000 monthly downloads, and ai-sdk-ollama, with 120,000. Exfiltrated data was sent to the GitHub account liuende501.
All Coverage
3 original reportsThe Backstory
The history behind this eventMiasma Supply-Chain Worm Source Code Leaks, Targeting AI Tools Including Claude and Cursor
Miasma is a supply-chain worm that evolved from Mini Shai-Hulud. It steals developer and CI/CD credentials before infecting npm and PyPI packages and GitHub repositories. The worm can poison configuration files for 13 AI coding tools, including Claude Code, Gemini CLI and Cursor, allowing malicious code to be triggered simply by opening a project and amplifying cascading risks across the open-source ecosystem.
SafeDep said on June 9, 2026, that compromised accounts had been uploading the “Miasma-Open-Source-Release” source-code repository to GitHub since June 8. The sample repository was subsequently taken down. The toolkit uses five layers of obfuscation and three C2 channels and can bypass GitHub environment protection rules. Its PyPI campaign affected 19 packages and 37 malicious releases.
Red Hat Cloud Services NPM Packages Compromised by Miasma Malware Targeting Claude Code and Cloud Credentials
NPM is a JavaScript package platform, and Red Hat’s @redhat-cloud-services components are used in its hybrid cloud console. Crucially, Miasma can spread through legitimate CI/CD release pipelines, steal GitHub credentials as well as AWS, Azure and GCP credentials, and implant persistent hooks in Anthropic Claude Code configurations.
Red Hat said attackers used an employee GitHub account compromised through a malicious VS Code extension to inject a workflow on May 29, 2026. Researchers found on June 1 that at least 32 packages and 96 versions had been affected. Microsoft published a six-stage analysis on June 2. Red Hat has removed the affected versions and said the compromised packages were not included in product builds.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →