As cited
Copy frozen at (site build).
threat intel
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
The Miasma campaign exploited a stolen Red Hat developer credential from underground markets to inject malicious packages into the npm registry, affecting 89 plus packages across three waves in early June. The attack demonstrated a structured threat model where harvested developer credentials are bought and weaponized weeks after theft, and included novel techniques such as forged SLSA provenance attestations and persistence mechanisms targeting AI coding assistants like Claude and Cursor. The campaign illustrates an emerging developer credential economy where infostealers, dark web markets, and supply chain compromises operate as coordinated layers in a single attack pipeline.
Why it matters: Development teams and package maintainers are directly exposed to credential harvesting and supply chain poisoning; security leaders should treat developer credentials as critical infrastructure, implement real-time secret neutralization, and enforce human-gated publishing controls since traditional endpoint detection lacks visibility into ephemeral CI/CD environments where attacks originate.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
The Miasma campaign, a self-propagating npm worm, compromised 89 packages across three waves starting June 1 by leveraging a stolen Red Hat developer credential that circulated in underground markets for seven weeks before weaponization. The attack produced valid provenance attestations that bypassed supply-chain integrity checks and introduced persistence mechanisms targeting artificial intelligence (AI) coding assistants. This incident illustrates an emerging threat model where harvested developer credentials flow through black markets for downstream exploitation by multiple threat actors.
Why it matters: Organizations shipping or consuming npm, PyPI, or GitHub dependencies face immediate risk from a structured economy that targets developer credentials as control-plane infrastructure; practitioners should implement phased threat exposure management with real-time secret neutralization and human-gated publishing controls, as traditional endpoint detection and response tools lack visibility into CI/CD environments where compromise occurs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
The Miasma campaign, a self-propagating npm worm, compromised 89 packages across three waves starting June 1 by leveraging a stolen Red Hat developer credential that circulated in underground markets for seven weeks before weaponization. The attack produced valid provenance attestations that bypassed supply-chain integrity checks and introduced persistence mechanisms targeting artificial intelligence (AI) coding assistants. This incident illustrates an emerging threat model where harvested developer credentials flow through black markets for downstream exploitation by multiple threat actors.
Why it matters: Organizations shipping or consuming npm, PyPI, or GitHub dependencies face immediate risk from a structured economy that targets developer credentials as control-plane infrastructure; practitioners should implement phased threat exposure management with real-time secret neutralization and human-gated publishing controls, as traditional endpoint detection and response tools lack visibility into CI/CD environments where compromise occurs.
- Source published
- First seen by Cybersecurity Tracker