Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

3eab3ec9304aa26081358330491d3cfeb55cc245

TLP:CLEAR
Active

SHA-1 Hash

Description

Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Pattern Type
STIX
Confidence
75%
Valid From
Jul 14, 2026 22:00
Total Sightings
0
Added
Jul 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 3eab3ec9304aa26081358330491d3cfeb55cc245

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.