Mini Shai-Hulud / Miasma / Hades multi-ecosystem supply-chain malware activity
Malware Activity
Summary
Hide ▲
Show ▼
The Mini Shai-Hulud / Miasma / Hades malware activity added malicious npm releases, GitHub Actions workflow abuse, and a related Go module compromise, increasing the risk of developer credential theft across trusted supply-chain workflows. The affected path spans LeoPlatform, RStreams, and the Verana Blockchain project, showing the operator's ability to move across package ecosystems. The payload uses install-time execution and stolen secrets to spread through registries, repositories, and CI/CD runners.
Related Happenings
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
GitHub npm version 12 hardens installs and token management
Security Tool/Service
H score11
First: 09.07.2026 19:49
Last: 09.07.2026 19:49
Sources 1
About this happening:
GitHub released npm version 12, making install-time scripts opt-in by default and tightening package publishing controls to reduce supply-chain risk. The update al...
GitHub npm version 12 hardens installs and token management
Security Tool/ServiceAbout this happening: GitHub released npm version 12, making install-time scripts opt-in by default and tightening package publishing controls to reduce supply-chain risk. The update al...
GitHub npm GAT publish-token mitigation guidance
Advisory/Mitigation
H score25
First: 09.07.2026 19:49
Last: 09.07.2026 19:49
Sources 1
About this happening:
GitHub is steering npm users away from long-lived publish tokens as npm GATs that bypass 2FA lose direct publishing and sensitive-management abilities. The recomme...
GitHub npm GAT publish-token mitigation guidance
Advisory/MitigationAbout this happening: GitHub is steering npm users away from long-lived publish tokens as npm GATs that bypass 2FA lose direct publishing and sensitive-management abilities. The recomme...
Codfish/semantic-release-action hit by network compromise
Incident
H score21
First: 26.06.2026 14:05
Last: 26.06.2026 14:05
Sources 1
How related:
"On June 24, 2026 at 15:39:06 UTC, an attacker force-pushed a malicious commit to codfish/semantic-release-action and redirected several version tags to point at the malicious commit," StepSecurity said.
About this happening:
The codfish/semantic-release-action GitHub Action was hit by a malicious commit force-push and tag redirection that caused trusted workflows to run attacker code. The...
Codfish/semantic-release-action hit by network compromise
IncidentHow related: "On June 24, 2026 at 15:39:06 UTC, an attacker force-pushed a malicious commit to codfish/semantic-release-action and redirected several version tags to point at the malicious commit," StepSecurity said.
About this happening: The codfish/semantic-release-action GitHub Action was hit by a malicious commit force-push and tag redirection that caused trusted workflows to run attacker code. The...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
Campaign
H score9
First: 23.06.2026 11:54
Last: 23.06.2026 11:54
Sources 1
About this happening:
A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
CampaignAbout this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
Timeline
-
26.06.2026 14:05 2 articles · 19d ago
Mini Shai-Hulud / Miasma / Hades multi-ecosystem supply-chain malware activity
Initial DisclosureThe earliest visible phase was a set of trojanized npm releases pushed through a likely breached maintainer account, with attackers abusing a short token window to publish poisoned versions. That foothold later extended into GitHub Actions and the Go ecosystem.
Show sources
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack — thehackernews.com — 26.06.2026 14:05
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack — thehackernews.com — 26.06.2026 14:05