----------------
🎯 Threat Intelligence
===================
🔹 npm Supply Chain Escalation: From Shai-Hulud to Miasma RAT
Unit 42's updated report documents a sharp escalation in npm supply chain attacks following the Shai-Hulud worm in September 2025. The worm automated compromise and redistribution of malicious packages, shifting npm attacks from isolated typosquatting to systematic, weaponized campaigns.
🔹 Campaign Timeline
April 2026: Two campaigns identified. "Shai-Hulud: The Third Coming" started April 22. "Mini Shai-Hulud" began April 29.
May 2026: TeamPCP continued the Mini Shai-Hulud campaign with two new waves. One introduced a credential-free initial access technique. The other generated the highest single-hour package count of any Shai-Hulud worm to date. Copycat activity has since complicated attribution.
June 2026: At least 32 packages under the @redhat-cloud-services npm namespace were compromised. The attacker bypassed code review entirely and pushed a payload named Miasma.
July 2026: Attackers compromised release pipelines of four core AsyncAPI GitHub repositories on July 14. The campaign, calling itself miasma-train-p1, published five trojanized packages:
• @asyncapi/[email protected]
• @asyncapi/[email protected]
• @asyncapi/[email protected]
• @asyncapi/[email protected]
• @asyncapi/[email protected]
The payload is assessed as a descendant of the Miasma RAT.
🔹 Core TTP Shifts
1. Wormable propagation: Payloads steal npm tokens and GitHub PATs to automatically infect and republish legitimate packages, as seen in the March 2026 Axios compromise.
2. Infrastructure-level persistence: Attackers embed into CI/CD pipelines for long-term, undetectable access to enterprise environments.
3. Multi-stage payloads: Dormant sleeper dependencies activate only under specific environmental conditions, evading automated scanners.
🔹 Attack Chain
• Initial Access: Credential-free techniques, stolen npm tokens, GitHub PATs
• Persistence: CI/CD pipeline compromise
• Execution: Miasma RAT and descendants
• Propagation: Automated republishing of trojanized packages
• Evasion: Sleeper dependencies with conditional activation
Monitor for campaign identifiers "miasma-train-p1" and "Shai-Hulud: The Third Coming" in infrastructure logs.
🔹 npm #SupplyChain #ShaiHulud #MiasmaRAT #ThreatIntelligence
🔗 Source: https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/?utm_campaign=u42+research-EN_nmpsupplychainattacks-x