Miasma is a self-propagating software supply-chain worm and credential stealer derived from Mini Shai-Hulud and associated with the TeamPCP malware ecosystem. It targets developers, CI/CD pipelines, development servers, and build environments through compromised software packages. Its lineage includes propagation through npm and PyPI, with stolen publishing credentials enabling further malicious releases. One npm campaign compromised 57 packages across more than 286 malicious versions.
Miasma uses heavily obfuscated JavaScript and the Bun runtime. An observed npm variant abuses native-build configuration command substitution to execute during installation without explicitly declaring package lifecycle scripts. It harvests AWS, Google Cloud, and Azure credentials, package-registry tokens, GitHub Actions secrets, and credentials from password stores including 1Password, gopass, and pass. On Linux, it can extract secrets directly from CI runner process memory. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories.
The worm implants persistent execution mechanisms in IDE and AI coding-assistant configurations, including those used by VS Code, Claude Code, Cursor, and Gemini. Configuration poisoning can also influence AI-generated code. Its evasion techniques include obfuscation, deceptive provenance attestations, and fake headers intended to mislead AI-assisted security review tools. Public availability of related source code has enabled derivative campaigns, so the malware's association with TeamPCP does not establish that every deployment is operated by that group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Miasma was a variant of Mini Shai-Hulud that propagated across those same open-source registries while harvesting credentials and poisoning configuration files.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A July FBI advisory (PDF) identified TeamPCP malware including CanisterWorm, SANDCLOCK, Mini Shai-Hulud and Miasma.
The GitHub fingerprint the attackers left behind – a repository description reading “Alright Lets See If This Works” turned up on over 320 infected repositories before researchers began pulling the thread. That string is not something random. In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
The GitHub fingerprint the attackers left behind – a repository description reading “Alright Lets See If This Works” turned up on over 320 infected repositories before researchers began pulling the thread. That string is not something random. In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
An infrastructure provider's networks have been breached and they were dealing with the Miasma worm. That worm, as it turns out, is pretty hard to catch and delete because it is self-spreading through IDE configuration settings and through AI assisted environments.
An infrastructure provider's networks have been breached and they were dealing with the Miasma worm. That worm, as it turns out, is pretty hard to catch and delete because it is self-spreading through IDE configuration settings and through AI assisted environments.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Les identifiants ciblés comprennent clés IAM, jetons OIDC, jetons Entra ID, comptes de service GCP, PATs et clés API; la liste inclut T1078 — Valid Accounts.
Attackers target a commonly used software dependency and hijack its latest version to inject malicious code to be executed in victim environments.
The bootstrapper writes an obfuscated JavaScript payload named _index.js. The Miasma lineage uses JavaScript-based obfuscation engines to make behavioral sandboxing and traditional signature-based detection difficult.
Active credential-stealing campaigns, such as Mini Shai-Hulud, Miasma, and Hades, embedding fake headers specifically engineered to fool AI-assisted review tools into marking code as benign.
including direct extraction from runner process memory via /proc/*/mem
Les cibles incluent des jetons OIDC AWS SSO, jetons Entra ID et refresh tokens, jetons GCP, GitHub App/OAuth/PAT, jetons GitLab Runner et jetons OAuth d’outils IA.
Les artefacts ciblés comprennent ~/.aws/credentials, fichiers Azure accessTokens.json et caches MSAL, bases GCP credentials.db/access_tokens.db, fichiers GitHub/GitLab de configuration, ainsi que des fichiers .env et credentials.json contenant des clés API.
It looks for more than one hundred environment variable names spanning source control, package registries, major cloud providers, container platforms, secret managers, and popular AI services.
The second stage delivers a modular runtime called Miasma. That framework can talk to remote servers... Primary control servers sat at a single IP on ports 8080, 8081, and 8091, with fallback discovery over several decentralized networks.
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
102 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer cité comme ciblant les pipelines CI/CD.
Infostealer-like malware associated with software supply-chain compromise. It targets CI/CD pipelines, development servers, build processes, and Azure CLI token artifacts to obtain API keys, cloud credentials, CI tokens, and deployment artifacts for post-compromise activity.
A publicly available malware/tool developed by TeamPCP; the content provides no further functional details.
Credential-stealing malware campaign that uses fake headers intended to cause AI-assisted reviewers to classify malicious code as benign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.