Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Miasma Worm Returns to npm

85.137.53.71

TLP:CLEAR
Active

IPv4 Address

Description

Four AsyncAPI npm packages were compromised in July 2026, delivering Miasma v3, a new variant of the worm previously found in Red Hat packages. The malicious versions (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) were published through AsyncAPI's legitimate GitHub Actions workflow using npm's OIDC integration, creating packages with valid provenance attestations. Unlike previous variants, this attack triggers when applications load the poisoned library rather than during installation. The payload downloads a second stage from IPFS, establishing a persistent Node.js backdoor with arbitrary shell command execution capabilities. While the codebase contains credential theft, propagation, and AI-tool poisoning modules, this deployment primarily functions as a remote access trojan. The attack began with an unauthorized commit to the repository's release branch, highlighting the importance of branch protection even when using trusted-p...

Sightings (0)

No sightings recorded yet

Details

Name / Label
Miasma Worm Returns to npm
Pattern Type
STIX
Confidence
75%
Valid From
Jul 15, 2026 16:00
Total Sightings
0
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 85.137.53.71

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.