Tracked campaign · npm
Miasma worm
npm worm that abuses binding.gyp action targets to execute credential-stealing shell commands during node-gyp compilation, bypassing lifecycle-script inspection.
50 packages attributednpm ecosystemosv source
Attribution basis
- shared malware fingerprint
- OSV advisory cluster
Sample attributed packages
nfets@0.0.116@otocolobus/node-icu-iana-from-windows@1.0.12@otocolobus/node-icu-iana-from-windows@1.0.8@otocolobus/node-icu-iana-from-windows@1.0.6autotel-subscribers@29.0.6autotel-eventcatalog@2.0.1autotel-mongoose@1.0.2autotel-mongoose@4.0.1autotel-mcp-instrumentation@29.0.2sharp@0.35.1@platformatic/rdkafka@4.0.0@platformatic/rdkafka@4.0.1sharp@0.35.1-rc.1sharp@0.35.1-rc.0@revizly/sharp@0.35.0-revizly36rclnodejs@1.9.0rclnodejs@2.1.0-beta.0node-env-resolver-aws@10.0.1@venos-inc/venos@0.1.2executable-stories-cypress@6.1.1executable-stories-jest@6.1.1executable-stories-playwright@6.1.1executable-stories-vitest@4.0.1executable-stories-vitest@6.1.1node-libcurl@2.1.0node-libcurl@5.1.2node-libcurl@2.1.0-5nfets@0.0.115sharp@0.35.0@venos-inc/venos@0.1.1