[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3h605wYBSK8SX2TUltmvTfvDv6NsrTXjE3NWTyZubPY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"92b73329-4a25-4301-8d05-91b263138f41","miasma-supply-chain-attack-poisons-npm-packages-github-actions-and-go-modules","e794f55a-6285-41b2-b734-f5e12729f38b","Miasma Supply Chain Attack Poisons npm Packages, GitHub Actions, and Go Modules","The Miasma Mini Shai-Hulud campaign represents a sophisticated multi-vector supply chain attack targeting developer tooling and CI\u002FCD pipelines by poisoning npm packages, abusing GitHub Actions, and extending into the Go ecosystem. Attackers exploit trust in open-source registries and automation workflows to silently steal developer credentials and CI\u002FCD secrets at build time, meaning compromised systems may never show obvious signs of intrusion. The use of AI coding assistant persistence is particularly alarming, as it embeds malicious behavior into tools developers inherently trust and frequently use. The 'Phantom Gyp' execution pattern and obfuscated Bun-staged payloads make detection significantly harder for traditional security tooling. This attack illustrates that the software supply chain — not just production systems — is now a primary battleground for credential theft and persistent compromise.","**Immediate actions:**\n- Audit all npm, Go module, and GitHub Actions dependencies used in active projects against known-compromised package lists (e.g., LeoPlatform, RStreams).\n- Rotate all CI\u002FCD secrets, API tokens, and developer credentials that may have been exposed in affected build pipelines.\n- Pin all third-party dependencies to verified, specific commit SHAs or cryptographically signed versions rather than mutable tags.\n\n**Long-term improvements:**\n- Implement a Software Composition Analysis (SCA) tool (e.g., Dependabot, Snyk, Socket.dev) to continuously scan open-source dependencies for malicious or anomalous behavior.\n- Establish an internal package mirror or artifact proxy (e.g., Artifactory, Nexus) to vet and control which external packages are permitted in builds.\n- Apply least-privilege principles to GitHub Actions workflows by restricting token permissions to only what each job requires.\n\n**Detection measures:**\n- Deploy runtime behavioral monitoring in CI\u002FCD environments to alert on unexpected outbound network connections or secret-access patterns during builds.\n- Enable audit logging for all package registry interactions and GitHub Actions workflow executions, and ship logs to a centralized SIEM for anomaly detection.\n- Monitor AI coding assistant plugins and IDE extensions for unauthorized updates or unexpected network activity.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 8: Audit Log Management","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST SP 800-218 (SSDF): PW.4 – Reuse Existing, Well-Secured Software","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 CM-3: Configuration Change Control","SLSA Framework Level 2+: Build Integrity and Provenance","OWASP Top 10 A06:2021 – Vulnerable and Outdated Components","OpenSSF Scorecard: Dependency Pinning and CI\u002FCD Security Best Practices","published","2026-06-25T20:20:57.134449+00:00","2026-06-25T20:20:56.833+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fmiasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem?utm_medium=feed","miasma-mini-shai-hulud-hits-leoplatform-npm-packages-and-github-actions-expands--d89331","Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"e343fcbd-c5e9-4c07-8654-903ff82126dd","2026-06-26","morning","ThreatNoir Morning Brief — June 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-26\u002Fthreatnoir-morning-brief-2026-06-26.mp3"]