CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 383

As cited

Copy frozen at (site build).

threat intel

What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials

The Miasma campaign exploited a stolen Red Hat developer credential from underground markets to inject malicious packages into the npm registry, affecting 89 plus packages across three waves in early June. The attack demonstrated a structured threat model where harvested developer credentials are bought and weaponized weeks after theft, and included novel techniques such as forged SLSA provenance attestations and persistence mechanisms targeting AI coding assistants like Claude and Cursor. The campaign illustrates an emerging developer credential economy where infostealers, dark web markets, and supply chain compromises operate as coordinated layers in a single attack pipeline.

Why it matters: Development teams and package maintainers are directly exposed to credential harvesting and supply chain poisoning; security leaders should treat developer credentials as critical infrastructure, implement real-time secret neutralization, and enforce human-gated publishing controls since traditional endpoint detection lacks visibility into ephemeral CI/CD environments where attacks originate.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials

The Miasma campaign, a self-propagating npm worm, compromised 89 packages across three waves starting June 1 by leveraging a stolen Red Hat developer credential that circulated in underground markets for seven weeks before weaponization. The attack produced valid provenance attestations that bypassed supply-chain integrity checks and introduced persistence mechanisms targeting artificial intelligence (AI) coding assistants. This incident illustrates an emerging threat model where harvested developer credentials flow through black markets for downstream exploitation by multiple threat actors.

Why it matters: Organizations shipping or consuming npm, PyPI, or GitHub dependencies face immediate risk from a structured economy that targets developer credentials as control-plane infrastructure; practitioners should implement phased threat exposure management with real-time secret neutralization and human-gated publishing controls, as traditional endpoint detection and response tools lack visibility into CI/CD environments where compromise occurs.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials

The Miasma campaign, a self-propagating npm worm, compromised 89 packages across three waves starting June 1 by leveraging a stolen Red Hat developer credential that circulated in underground markets for seven weeks before weaponization. The attack produced valid provenance attestations that bypassed supply-chain integrity checks and introduced persistence mechanisms targeting artificial intelligence (AI) coding assistants. This incident illustrates an emerging threat model where harvested developer credentials flow through black markets for downstream exploitation by multiple threat actors.

Why it matters: Organizations shipping or consuming npm, PyPI, or GitHub dependencies face immediate risk from a structured economy that targets developer credentials as control-plane infrastructure; practitioners should implement phased threat exposure management with real-time secret neutralization and human-gated publishing controls, as traditional endpoint detection and response tools lack visibility into CI/CD environments where compromise occurs.

VendorsMicrosoftGitHubLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary