The ‘Miasma’ worm source code briefly leaked on GitHub
For a limited period, the Miasma credential-stealing attack architecture was made available on GitHub. Recently, supply-chain hacks have been used to target open-source ecosystems.
With many of the same characteristics, methods, and even code as the earlier Shai-Hulud worm that was previously posted on GitHub, Miasma seems to be a development of that worm.
After infecting a developer's computer, the virus utilizes the build environment and cloud credentials to compromise trustworthy repositories and packages. Trojanized versions are then published to infect developers further down the chain.
This autonomous, worm-like self-propagation mechanism has the ability to spread swiftly, possibly transforming a single breach into a massive supply chain assault.
High-profile attacks aga...

