Miasma Malware Hits npm & GitHub Actions Supply Chain
đźź High |Â Source: The Hacker News A malware family known as Miasma (also linked to Mini Shai-Hulud and Hades) has expanded its supply chain attack campaign to compromise npm packages belonging to LeoPlatform and RStreams, abuse GitHub Actions workflows, and spread into the Go ecosystem. This represents an ongoing, evolving threat targeting developer toolchains and CI/CD pipelines. The broad reach across multiple package registries and automation platforms significantly increases the potential blast radius for downstream organisations. ...