Skip to content

Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages

Cybersecuritynews Tushar Subhra Dutta June 26, 2026

Supply chain attackers are getting more creative, and the latest threat is proof of that. A malware campaign known as Miasma has been caught hiding inside widely used npm packages, using a clever mix of tools and techniques to stay hidden while stealing sensitive developer credentials. The attack involves packages tied to the LeoPlatform and […]

Extracted Entities

Malware (2)

Platforms (1)

Tools (1)