# Miasma worm source code leaked on GitHub

Published: 2026-06-10 · Severity: critical · Sectors: technology
Canonical: https://vorant.io/reports/79242696-445f-47c6-a8ed-5a3e4bdbcca0/miasma-worm-source-code-leaked-on-github

> The Miasma credential-stealing framework targeting open-source supply chains was deliberately leaked on GitHub, revealing autonomous propagation capabilities and a destructive dead-man switch.

The Miasma attack framework, which evolved from the earlier Shai-Hulud worm, was deliberately leaked on GitHub through multiple compromised developer accounts. The malware operates as a self-propagating worm that infects developer machines, steals build environment and cloud credentials, and uses them to compromise legitimate repositories and packages. It publishes trojanized versions to infect downstream developers, creating a cascading supply-chain attack. Miasma has been linked to attacks on Red Hat npm packages and 73 Microsoft GitHub repositories.

Analysis of the leaked source code reveals sophisticated capabilities including credential harvesting from cloud providers, CI/CD systems, password managers, Kubernetes, and secret stores. The framework requires no command-and-control infrastructure, instead using GitHub itself for operations. It can compromise npm, PyPI, and RubyGems packages, GitHub repositories and Actions workflows, and JFrog Artifactory instances. The malware also features lateral movement via SSH and AWS Systems Manager, and can poison AI coding tool configurations including Claude, Gemini, Cursor, Copilot, Kiro, and Cline.

A notable feature is a destructive dead-man switch that monitors stolen GitHub tokens every minute and, if revoked, executes a recursive deletion command targeting the user's home and Documents folders. The malware employs a five-stage build pipeline generating unique payloads using AES-256-GCM encryption, randomized obfuscation, and three-layer encryption wrapping to evade signature-based detection. The leak is expected to accelerate supply-chain attacks as threat actors adopt and modify the code, similar to the pattern following the Shai-Hulud leak.

## Mentioned in this report

- Malware: Miasma, Shai-Hulud

Source reporting: https://www.bleepingcomputer.com/news/security/the-miasma-worm-source-code-briefly-leaked-on-github/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/79242696-445f-47c6-a8ed-5a3e4bdbcca0/miasma-worm-source-code-leaked-on-github.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
