Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages

d2aa3f9057c6f3295766aabed0a71a369353d6eb665049a45fd407fd55020fdb

TLP:CLEAR
Active

SHA-256 Hash

Description

A fresh wave of the Miasma Mini Shai-Hulud supply chain campaign compromised legitimate npm packages under the @immobiliarelabs scope on June 26, 2026. The attack targeted Backstage plugins used for GitLab integration and LDAP authentication, affecting 22 package versions across multiple releases. The malware employs sophisticated techniques including hidden payloads that bypass standard package reviews, steals developer credentials and CI/CD secrets, and exploits GitHub Actions workflows for propagation. The campaign appears linked to a compromised upstream GitHub Action (codfish/semantic-release-action) and leverages deployment-triggered workflows for execution. Stolen credentials include npm tokens, GitHub tokens, cloud credentials, SSH keys, and various authentication secrets, which are exfiltrated to attacker-controlled repositories for further propagation across the ecosystem.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 15:12
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of d2aa3f9057c6f3295766aabed0a71a369353d6eb665049a45fd407fd55020fdb

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.