QooryBeta
Back to narratives
SecurityActive
Conversation intelligence

Shai-Hulud/Miasma malware variant attacks npm packages from LeoPlatform

A new variant of the Shai-Hulud/Miasma malware compromised 20-23 npm packages from the LeoPlatform project, affecting over 50,000 monthly downloads. The attack uses a binding.gyp file to bypass lifecycle script scanners and steals credentials for GitHub, npm, cloud services, and AI coding tools.

Heat
86
Confidence
95%
Evidence
7
Updated

Why It Happened

The compromised npm developer account 'czirker' was used to publish malicious packages that execute during npm install via a preconfigured binding.gyp file, enabling credential theft and further supply chain compromise.

Outcome So Far

Affected packages identified and published in security reports; 338–408 GitHub repositories found with stolen credentials so far. Mitigation steps are being shared by security firms.

Actors

CZczirkercompromised npm developer account
LELeoPlatformaffected project
Timeline order

Post
Parent event 01

X conversation update

2 related posts from @OX__Security, @abh1sek

Related posts@OX__Security@abh1sek
@OX__Security
Open on X2.8K views · 18 likes · 8 reposts
@abh1sek
Open on X395 views · 5 likes · 2 reposts

Post
Parent event 02

safedepio notes Miasma worm's bypass technique

safedepio tweet explains Miasma worm used binding.gyp instead of postinstall to bypass lifecycle script scanners; targets multiple ecosystems.

Related posts@JFrogSecurity@MosheTov@safedepio5 posts
@JFrogSecurity
Open on X5.1K views · 54 likes · 19 reposts
@MosheTov
Open on X2.5K views · 33 likes · 9 reposts
@safedepio
Open on X372 views · 12 likes · 5 reposts
@OX__Security
Open on X270 views · 9 likes · 2 reposts
@SlowMist_Team
Open on X6.5K views · 7 likes · 1 reposts