The malware didn’t wait for npm install. It waited for you to open the project.
That’s the part of the Miasma campaign that should rearrange your threat model. A self-propagating npm worm spent early June compromising dozens of packages across Red Hat, Microsoft Azure, and Vapi.ai namespaces, and somewhere around its second wave it stopped relying on package installation altogether. Instead it dropped quiet little configuration files into project directories: .claude/settings.json for Claude Code, .cursor/rules for Cursor, equivalents for Gemini CLI and VS Code. The next time a developer opened that repo in an AI-assisted editor, the backdoor ran. No install step. No script execution an EDR agent could catch. Just an instruction-layer override that quietly tells your AI assistant what to do. This is where modern cybersecurity stops being about blocking payloads and starts being about who, or what, your tools trust by default.
The trigger moved to your editor
For years the supply chain conversation has fixated on install-time code execution. Kill the lifecycle hooks, run with --ignore-scripts, monitor preinstall and postinstall, and you’ve closed the door. Miasma walked through the window.
Its second wave used a 157-byte binding.gyp file to trigger execution during install, sidestepping the preinstall-script monitoring defenders had just deployed. Then the third wave abandoned package installation entirely and shifted to repository-level config files that fire when a developer opens the project in their IDE. Each defensive response created a new evasion target, and the iteration cycle was measured in days.
The AI assistant angle is the genuinely new wrinkle. These aren’t trojanized extensions or compromised plugins. They’re plain-text instruction files that silently alter how your coding agent behaves the moment you load the project. The attacker’s hidden directions can shape AI-generated code, nudging in subtle vulnerabilities that look exactly like helpful suggestions. The Five Eyes intelligence agencies warned this month that AI’s threat to security operates on a timeline of months, not years. Anthropic’s Fable 5 model, the supposedly safe one, was jailbroken within days of release. Treating an AI coding assistant as an obedient junior dev that reads whatever instructions it finds is the same category of mistake.
This is the whole supply chain problem now
Strip away the AI novelty and Miasma is a credential machine. Every developer environment that installed a poisoned package became a harvesting node, sweeping GitHub tokens, npm publishing tokens, cloud credentials, SSH keys, and .env files, then using that fresh access to compromise the next package in the chain.
The timestamp matters more than the technique. A Red Hat employee’s GitHub credential and session cookie showed up in infostealer logs on April 13, sat in underground markets for roughly seven weeks, and got weaponized on June 1. That dwell time is the business model. Researchers at Tenable call the surrounding ecosystem the Developer Credential Economy: commodity infostealers generate the credentials, underground markets distribute them, and multiple unrelated actors weaponize them downstream.
Two assumptions died here. The first is that cryptographic provenance saves you. Miasma’s first-wave packages carried valid SLSA Build Level 3 attestations, the highest tier of supply chain integrity verification. The signatures were accurate. Red Hat’s real pipeline built the packages. The pipeline just happened to contain malware at the time. A signed attestation proves which pipeline built a thing, not that the pipeline was clean.
The second dead assumption is that endpoint threat detection catches this. The credential theft happens inside ephemeral CI/CD runners that spin up, exfiltrate secrets, and tear down before any analyst could triage an alert. EDR watches execution; the damage here is exposure. A firewall and a smart threat-protection stack at the perimeter never see the build stage where the secrets walk out.
What to actually do
None of this requires a new product. It requires treating developer environments as control-plane infrastructure and applying real security hardening to them.
- Audit cloned repos for AI-agent config files. Scan for
.claude/settings.json,.cursor/rules, and Gemini/VS Code equivalents that nobody on your team committed. Add them to your package intake checks alongsidebinding.gypand lifecycle hooks. - Run
--ignore-scriptsand quarantine new versions. Use aminimumReleaseAgecontrol to hold fresh package versions before consumption, so a malicious publish has to survive scrutiny instead of landing instantly. - Monitor underground markets for your developers’ credentials. Continuous dark-web monitoring of GitHub, npm, PyPI, and Docker Hub accounts, with automated rotation on a hit, collapses that seven-week window to something survivable.
- Gate publishing with a human. Staged publishing with a 2FA approval step breaks the steal-token-then-republish automation that lets these worms self-propagate.
- Tighten OIDC scope and kill ghost credentials. Limit
id-token: writeto release workflows on protected branches, and hunt the dormant service accounts and unrotated keys that hand attackers ready-made pivots.
Build your defense in depth around the assumption that a credential will leak and a config file will lie. Then rehearse the incident response for it: a developer credential is loose, packages you depend on are suspect, and your AI assistant may have been taking instructions from someone else.
Brute-force protection and a tuned firewall still matter. They just aren’t where this fight is anymore.
Sources
- What the Miasma campaign reveals about the new supply chain threat model
- Five Eyes agencies sound alarm about AI’s threat to cybersecurity
- Anthropic’s Fable 5 Model Jailbroken Within Days
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
