PkgRadar

Tracked campaign · npm

Miasma worm

npm worm that abuses binding.gyp action targets to execute credential-stealing shell commands during node-gyp compilation, bypassing lifecycle-script inspection.

50 packages attributednpm ecosystemosv source

First seen 2025-06-02

Attribution basis

These are the signal classes linking the members of this campaign — the broad evidence categories we use to attribute a package, not the raw indicators themselves.

Sample attributed packages

PkgRadar attributes coordinated supply-chain campaigns and blocks their packages at the CI gate. Start free or see all tracked campaigns.