Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Miasma Worm Returns to npm

0
Medium
Published: 07/15/2026 (07/15/2026, 14:20:02 UTC)
Source: AlienVault OTX General

Description

Four AsyncAPI npm packages were compromised in July 2026, delivering Miasma v3, a new variant of the worm previously found in Red Hat packages. The malicious versions (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) were published through AsyncAPI's legitimate GitHub Actions workflow using npm's OIDC integration, creating packages with valid provenance attestations. Unlike previous variants, this attack triggers when applications load the poisoned library rather than during installation. The payload downloads a second stage from IPFS, establishing a persistent Node.js backdoor with arbitrary shell command execution capabilities. While the codebase contains credential theft, propagation, and AI-tool poisoning modules, this deployment primarily functions as a remote access trojan. The attack began with an unauthorized commit to the repository's release branch, highlighting the importance of branch protection even when using trusted-publisher mechanisms.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 12:41:41 UTC

Technical Analysis

The Miasma v3 worm compromised four AsyncAPI npm packages (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) by exploiting an unauthorized commit to the repository's release branch. The attacker leveraged the legitimate GitHub Actions workflow with npm's OIDC integration to publish malicious package versions that carried valid provenance attestations, bypassing typical supply chain trust mechanisms. Unlike earlier Miasma variants that triggered on installation, this version activates when the poisoned library is loaded by an application. Upon activation, it downloads a second-stage payload from the InterPlanetary File System (IPFS), establishing a persistent Node.js backdoor capable of executing arbitrary shell commands. While the malware includes capabilities for credential theft, lateral movement, and AI-tool poisoning, this deployment primarily functions as a remote access trojan. The incident highlights the critical importance of enforcing branch protection controls and reviewing CI/CD workflows to prevent unauthorized changes, as reliance on provenance attestations alone is insufficient to prevent supply chain compromises.

Potential Impact

Systems that load the compromised AsyncAPI npm packages risk having a persistent backdoor installed, allowing attackers to execute arbitrary shell commands remotely. This can lead to unauthorized remote access, potential credential theft, lateral movement within networks, and further compromise of affected environments. The attack undermines trust in the software supply chain by abusing legitimate publishing workflows and valid provenance attestations. Although no active exploitation in the wild has been reported, the malware's advanced capabilities pose a significant potential risk if leveraged by threat actors.

Defensive Guidance

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should verify the integrity of AsyncAPI npm packages before use and monitor for official updates or patches from AsyncAPI. Enforcing strict branch protection on release branches and auditing CI/CD workflows for unauthorized commits are critical to prevent similar supply chain attacks. Since this attack abuses legitimate publishing workflows and provenance attestations, additional controls beyond provenance verification are necessary to secure the software supply chain.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://research.jfrog.com/post/miasma-worm-returns-to-npm/"]
Adversary
null
Pulse Id
6a579712c94f47186288661d
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainobfuscator.io

Ip

ValueDescriptionCopy
ip85.137.53.71

Url

ValueDescriptionCopy
urlhttp://85.137.53.71:8080
urlhttp://85.137.53.71:8081
urlhttp://85.137.53.71:8091

Threat ID: 6a579dc068715ace43e91708

Added to database: 07/15/2026, 14:48:32 UTC

Last enriched: 08/15/2026, 12:41:41 UTC

Last updated: 08/16/2026, 12:41:34 UTC

Views: 143

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses