🎯 Threat Intelligence

🔹 npm Supply Chain Escalation: From Shai-Hulud to Miasma RAT

Unit 42's updated report documents a sharp escalation in npm supply chain attacks following the Shai-Hulud worm in September 2025. The worm automated compromise and redistribution of malicious packages, shifting npm attacks from isolated typosquatting to systematic, weaponized campaigns.

🔹 Campaign Timeline

April 2026: Two campaigns identified. "Shai-Hulud: The Third Coming" started April 22. "Mini Shai-Hulud" began April 29.

May 2026: TeamPCP continued the Mini Shai-Hulud campaign with two new waves. One introduced a credential-free initial access technique. The other generated the highest single-hour package count of any Shai-Hulud worm to date. Copycat activity has since complicated attribution.

June 2026: At least 32 packages under the @redhat-cloud-services npm namespace were compromised. The attacker bypassed code review entirely and pushed a payload named Miasma.

July 2026: Attackers compromised release pipelines of four core AsyncAPI GitHub repositories on July 14. The campaign, calling itself miasma-train-p1, published five trojanized packages: • @asyncapi/generator@3.3.1 • @asyncapi/specs@6.11.2 • @asyncapi/specs@6.11.2-alpha.1 • @asyncapi/generator-helpers@1.1.1 • @asyncapi/generator-components@0.7.1

The payload is assessed as a descendant of the Miasma RAT.

🔹 Core TTP Shifts

  1. Wormable propagation: Payloads steal npm tokens and GitHub PATs to automatically infect and republish legitimate packages, as seen in the March 2026 Axios compromise.

  2. Infrastructure-level persistence: Attackers embed into CI/CD pipelines for long-term, undetectable access to enterprise environments.

  3. Multi-stage payloads: Dormant sleeper dependencies activate only under specific environmental conditions, evading automated scanners.

🔹 Attack Chain • Initial Access: Credential-free techniques, stolen npm tokens, GitHub PATs • Persistence: CI/CD pipeline compromise • Execution: Miasma RAT and descendants • Propagation: Automated republishing of trojanized packages • Evasion: Sleeper dependencies with conditional activation

Monitor for campaign identifiers "miasma-train-p1" and "Shai-Hulud: The Third Coming" in infrastructure logs.

🔹 npm #SupplyChain #ShaiHulud #MiasmaRAT #ThreatIntelligence

🔗 Source: https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/?utm_campaign=u42+research-EN_nmpsupplychainattacks-x