Miasma is a self-propagating software supply-chain threat cluster associated with malicious npm, PyPI, and direct GitHub repository compromises targeting developer ecosystems, CI/CD pipelines, and open-source maintainers. It is widely described as a rebrand or evolution of Mini Shai-Hulud and is closely linked in reporting to the broader Shai-Hulud, TeamPCP, and Hades activity clusters. Hades is frequently characterized as a later evolution of Miasma, while some later malware samples using Miasma branding have been assessed as copycats or false-flag reuse rather than the same operator. The actor’s operations focus on compromising maintainer accounts, publish tokens, and trusted release workflows, then republishing trojanized packages or pushing malicious code directly into source repositories. Observed targets include open-source package ecosystems and developer-heavy environments, with notable impact on cloud, software, bioinformatics, computational biology, genotype-phenotype analysis, and Microsoft Azure-related projects. Activity has affected npm and PyPI packages, GitHub repositories, and GitHub Actions workflows, including trusted publishing paths that produced apparently legitimate provenance attestations. Miasma malware families are centered on credential theft and worm-like propagation. Reported payloads harvest GitHub, npm, PyPI, RubyGems, JFrog, and cloud credentials, including AWS, Azure, and GCP material, as well as Kubernetes, Vault, SSH, Docker, shell-history, environment, and AI developer-tool configuration data. Exfiltration has repeatedly been conducted through GitHub infrastructure, including creation of public repositories under victim-controlled identities and use of public commits as command, configuration, and data channels. Some variants also used blockchain- or decentralized-network-assisted fallback mechanisms. Tradecraft attributed to Miasma and its evolutions includes malicious preinstall hooks, runtime-module backdooring, Python startup-hook abuse, native-extension execution, obfuscated Bun-based loaders, encrypted multi-stage payload delivery, GitHub Actions workflow abuse, OIDC trusted-publisher token minting, Sigstore/SLSA provenance abuse, persistence through IDE and AI-assistant configuration files, background token-monitor services, and destructive dead-man-switch logic that can wipe user data if stolen tokens are revoked. Additional reporting describes anti-analysis checks for virtualized environments, endpoint tooling, and Russian locale settings, as well as prompt-injection text intended to disrupt LLM-assisted malware triage. The cluster’s dominant objective is theft of credentials and secrets to enable recursive propagation across package registries, repositories, and downstream developer environments. Although some variants include remote shell, lateral movement, and wiper functionality, the core pattern is large-scale credential harvesting and self-spreading compromise of software supply chains rather than ransomware or overt extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A suspected copycat actor using publicly released Shai-Hulud code to compromise package ecosystems, abuse trusted publishing, and exfiltrate stolen data.
Referenced as a prior campaign that the malware appears to mimic for misdirection; the report explicitly says the current attack is not attributed to it.
Branding and artifact naming overlap with an earlier Miasma toolkit, but the content explicitly says attribution is inconclusive and may reflect code reuse, imitation, or deliberate mislabeling.
Supply-chain credential theft campaign delivered through compromised npm packages and developer accounts, using multi-stage droppers to steal GitHub, npm, and cloud credentials and upload stolen data to GitHub.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.