# Miasma Worm Source Code Leaks on GitHub: Supply-Chain Attacks Enter a Dangerous New Phase


The disclosure of the Miasma credential-stealing framework on GitHub marks a critical inflection point in supply-chain security. What began as a targeted attack tool used by sophisticated threat actors is now freely available source code, accelerating an already alarming trend of supply-chain compromise at an unprecedented scale.


Miasma represents the evolution of earlier malware like Shai-Hulud, combining autonomous worm-like propagation with multi-stage encryption and zero command-and-control infrastructure requirements. Its ability to steal credentials from developers' machines and weaponize them against entire software ecosystems poses an existential threat to open-source security.


## The Threat: A Worm Without Masters


Unlike traditional malware that relies on centralized command-and-control servers, Miasma operates autonomously and requires no external infrastructure. Instead, it uses GitHub itself as its coordination mechanism—turning one of the world's largest code repositories into an unwitting accomplice.


The malware's core function is ruthlessly simple: compromise a developer machine, harvest their credentials, and use those credentials to inject malicious code into legitimate packages and repositories. Once contaminated packages are published to public package managers, the cycle repeats downstream, infecting any developer who downloads the trojanized software.


This self-propagating mechanism transforms a single infection into a cascading supply-chain attack that can spread across thousands of projects within hours.


## Background and Context: Evolution of Supply-Chain Threats


Miasma didn't appear in a vacuum. It evolved directly from Shai-Hulud, an earlier supply-chain worm whose source code was leaked on GitHub in 2024. That leak triggered a surge in variants and refined attacks, and researchers warned at the time that public disclosure would accelerate the threat.


The prediction proved accurate.


### Timeline of Escalation


| Date | Event | Impact |

|------|-------|--------|

| 2024 | Shai-Hulud source code leaked | Initial supply-chain worm becomes public knowledge |

| 2024-2025 | Red Hat npm attack; 73 Microsoft GitHub repos compromised | Proof-of-concept attacks against major organizations |

| June 2026 | Miasma source code deliberately leaked | Advanced variant now freely available to all threat actors |


Researchers at SafeDep discovered the Miasma leak via dozens of compromised developer accounts, each containing a repository labeled "Miasma-Open-Source-Release." The naming convention strongly suggests this was an intentional release by threat actors, not an accidental exposure—a strategy that mirrors the earlier Shai-Hulud leak.


The question researchers are asking: *Why would threat actors voluntarily release their tools?*


The answer reveals a sophisticated understanding of the threat landscape: distributing source code to other malicious actors accelerates adoption, fragment attribution, and ensures continued innovation even if one variant is identified and mitigated.


## Technical Details: How Miasma Operates


Miasma functions across five distinct stages, each designed to maximize impact while evading detection.


### The Attack Chain


Stage 1: Initial Compromise

The malware infects a developer's local machine through phishing, trojanized software downloads, or compromised third-party dependencies.


Stage 2: Credential Harvesting

Once installed, Miasma systematically extracts credentials from:

  • Cloud provider accounts (AWS, Azure, GCP)
  • CI/CD systems (GitHub Actions, GitLab CI, Jenkins)
  • Password managers (1Password, LastPass, Vault)
  • Kubernetes configurations
  • Container registries and secret stores
  • SSH key files

  • Stage 3: Payload Generation

    The toolkit generates unique, encrypted payloads for each target using a five-layer encryption process:

  • Per-file AES-256-GCM encryption of embedded assets
  • Randomized string obfuscation
  • Source code transformations
  • JavaScript obfuscation
  • Self-extracting loader with triple encryption

  • This multilayered approach ensures that each generated sample differs significantly from previous builds, rendering signature-based detection and static analysis nearly ineffective.


    Stage 4: Repository Poisoning

    Using stolen credentials, Miasma compromises legitimate repositories and publishes trojanized packages to:

  • npm (Node.js packages)
  • PyPI (Python packages)
  • RubyGems (Ruby packages)
  • GitHub repositories and Actions workflows
  • JFrog Artifactory instances

  • Stage 5: Lateral Movement and Persistence

    The malware spreads laterally through SSH key abuse and AWS Systems Manager, establishing persistent footholds across interconnected infrastructure.


    ### The C2-Less Design: GitHub as Command Center


    A critical innovation in Miasma's architecture is its elimination of external command-and-control infrastructure. Threat actors traditionally rely on centralized servers to coordinate attacks, but these servers become forensic artifacts and takedown targets.


    Miasma bypasses this entirely by using GitHub repositories as its control mechanism. Compromised machines poll GitHub for instructions encoded in repository contents, encrypted data, or commit messages. GitHub's legitimacy as a platform means this traffic blends seamlessly with normal developer activity, evading network-based detection.


    ## Key Features Revealed in Leaked Code


    ### The Dead-Man Switch


    One of the most unsettling features in Miasma's source code is a destructive dead-man switch. When the malware uses a stolen GitHub token to exfiltrate data, it installs a monitor that checks the token's validity every 60 seconds.


    If the token is revoked—indicating a defender or the victim has discovered the compromise—the switch executes:


    rm -rf ~/
    rm -rf ~/Documents

    This command recursively deletes all files in the user's home directory and Documents folder, destroying evidence and rendering the system unusable. The monitor persists as a systemd user service (Linux) or LaunchAgent (macOS) and remains active for up to 72 hours, ensuring that even delayed token revocations trigger catastrophic data destruction.


    This feature transforms token revocation—typically a remediation step—into a destructive act, creating a perverse incentive for victims to delay detection.


    ### AI Tool Poisoning


    Miasma includes a novel feature that poisons configuration files for AI coding assistants, including:

  • Claude
  • Gemini
  • Cursor
  • Copilot
  • Kiro
  • Cline

  • By compromising AI tool configurations, threat actors can inject malicious instructions into the context that these tools receive, potentially causing developers to unknowingly generate or accept compromised code.


    ## Implications for Open-Source Security


    The supply-chain attack landscape has fundamentally shifted. Before Miasma's public release, threat actors operated with some degree of operational security—their tools were targeted, their methods somewhat proprietary. Now, with source code freely available, we face a scenario where:


    1. Low-barrier entry: Threat actors with minimal technical expertise can deploy variants of Miasma

    2. Rapid iteration: Multiple groups can simultaneously improve and adapt the malware

    3. Ecosystem-wide contamination: The volume and diversity of attacks will overwhelm existing detection capabilities

    4. Persistent compromise: The dead-man switch and lateral movement features ensure that remediation is difficult and costly


    Package managers like npm, PyPI, and RubyGems—trusted as critical infrastructure by millions of developers—have become primary attack surfaces.


    ## Recommendations for Developers and Organizations


    ### Immediate Actions


  • Rotate all credentials associated with GitHub, npm, PyPI, RubyGems, and cloud platforms
  • Audit recent package publishes to repositories you maintain; look for unexpected commits or versions
  • Review GitHub Actions workflows for unauthorized modifications
  • Check SSH key access logs for suspicious activity
  • Inspect password manager and CI/CD logs for exfiltration attempts

  • ### Dependency Management


  • Pin project dependencies to specific, vetted versions rather than accepting automatic updates
  • Introduce multi-day delays before adopting newly released package updates, allowing time for community scrutiny
  • Validate new builds in isolated test environments before promoting to production
  • Monitor package integrity using cryptographic verification where available

  • ### Detection and Response


  • Implement network monitoring to detect unusual GitHub API traffic patterns
  • Monitor for token revocations followed by filesystem manipulation attempts
  • Scan for systemd user services and macOS LaunchAgents that may represent persistent malware
  • Audit developer machine configurations, particularly cloud credential storage

  • ### Defensive Posture


  • Reduce credential scope using IAM policies that limit what stolen credentials can do
  • Enable hardware security keys for critical GitHub and cloud accounts
  • Enforce secrets management tools that rotate credentials automatically
  • Segment development infrastructure to limit lateral movement

  • ---


    ## HackWire Analysis


    The Miasma leak represents a deliberate strategy shift by threat actors—one that prioritizes ecosystem-wide contamination over operational stealth. By releasing source code, attackers ensure that even if their specific variant is detected and mitigated, dozens of improved variants will emerge from other groups.


    This pattern mirrors historical precedent in malware development: once source code leaks, the threat multiplies exponentially. The Shai-Hulud leak predicted this outcome, and the timeline vindicates those warnings.


    What's most concerning is the fundamental asymmetry now exposed in supply-chain security. Defenders must secure millions of individual packages, every update, every build. Attackers only need to compromise one. Miasma's five-stage encryption and payload randomization ensure that signature-based detection will fail en masse. The dead-man switch turns a standard remediation technique (token revocation) into a liability.


    The open-source ecosystem is now operating in a new threat model where trust in public repositories cannot be assumed. Organizations cannot wait for the industry to react—they must assume compromise and act accordingly. That means extended delays before adopting updates, cryptographic verification of build outputs, and aggressive monitoring of development infrastructure.


    The next 90 days will reveal whether the ecosystem can adapt faster than threat actors can weaponize Miasma variants. Early indicators suggest the opposite. — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)