[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIh5Wlw2goF5XS9L6KtsyIPzeRIffOVIj2zAUCLvEh9M":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"4a2ab69e-25d2-4ade-bbf5-fa943f509534","miasma-campaign-poisons-immobiliarelabs-npm-packages-via-cicd-privilege-escalation","11db96bb-1a6a-472f-88e4-764a47fc66bd","Miasma Campaign Poisons ImmobiliareLabs npm Packages via CI\u002FCD Privilege Escalation","The Miasma Mini Shai-Hulud campaign demonstrates how attackers can weaponize legitimate software distribution channels by compromising maintainer infrastructure and injecting malicious payloads into trusted npm packages. By exploiting a privilege escalation flaw in GitHub Actions deployment workflows and a compromised third-party action (codfish\u002Fsemantic-release-action), attackers gained the ability to publish malicious package versions without raising immediate suspicion. Developer and CI\u002FCD secrets were silently exfiltrated, meaning downstream consumers of these packages were exposed without any visible indicators of compromise. This attack underscores the cascading trust problem in modern software supply chains: one compromised maintainer or third-party action can propagate malicious code to thousands of dependent projects.","**Immediate actions:**\n- Audit all npm packages published under your organization's scope for unexpected version releases or modified package contents.\n- Rotate all npm publishing tokens, CI\u002FCD secrets, and deployment credentials that may have been exposed through compromised GitHub Actions workflows.\n- Pin third-party GitHub Actions to specific commit SHAs rather than mutable tags to prevent silent substitution of malicious versions.\n\n**Long-term improvements:**\n- Implement mandatory code signing and provenance attestation (e.g., npm provenance, Sigstore) for all published packages to verify authorship integrity.\n- Enforce least-privilege permissions on GitHub Actions workflows, restricting `id-token: write` and deployment permissions to only workflows that explicitly require them.\n- Establish a vetted allowlist of approved third-party GitHub Actions and require security review before any new external action is introduced into CI\u002FCD pipelines.\n\n**Detection measures:**\n- Enable npm publish audit logging and alert on any package version release that was not initiated through a known, approved CI\u002FCD pipeline.\n- Deploy software composition analysis (SCA) tools in CI\u002FCD pipelines to detect unexpected changes in transitive dependencies or package checksums.\n- Monitor GitHub Actions workflow logs for anomalous secret access patterns or unexpected interactions with npm registries.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST SP 800-204D: Securing Software Supply Chains","NIST AC-6: Least Privilege","NIST SI-7: Software, Firmware, and Information Integrity","SLSA Framework Level 2-3: Build Integrity and Provenance","OpenSSF Scorecards: Pinned-Dependencies Check","NIST CSF ID.SC-3: Suppliers and Third-Party Partners Risk Management","GDPR Article 32: Security of Processing (for EU-exposed developer data)","published","2026-06-26T22:20:39.652354+00:00","2026-06-26T22:20:39.576+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fmiasma-mini-shai-hulud-hits-immobiliarelabs-npm-packages?utm_medium=feed","miasma-mini-shai-hulud-hits-immobiliarelabs-npm-packages-0339d9","Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49,55],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"5f0612c2-3bb7-46ad-8745-0d336403de73","2026-06-28","afternoon","ThreatNoir Weekend Brief — June 28","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-28\u002Fthreatnoir-afternoon-brief-2026-06-28.mp3",{"id":56,"date":57,"edition":58,"title":59,"audio_url":60},"1c868be4-18a9-45df-b7c7-378ff66e0d85","2026-06-27","morning","ThreatNoir Weekend Brief — June 27","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-27\u002Fthreatnoir-morning-brief-2026-06-27.mp3"]