What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
2026-06-23T20:52:18Z•21eca9ca8cc2a2a28093e81cc7538f05321adac473f3a4e5640f2eca981b622f
ai-coding-assistantscisa-bod-26-04ctemdeveloper-credential-economydeveloper-credentialsinfostealermiasmamicrosoft-patch-tuesdaymini-shai-huludnpmoracle-cspupersistencepoisoned-packagesprovenance-bypassred-hatslsasupply-chainvulnerability-managementwormzero-day
What happened
This feed aggregates June 2026 Tenable analysis and advisories: a novel supply-chain campaign (“Miasma”)—a self-propagating npm worm derived from Mini Shai-Hulud—leveraged a stolen developer session cookie (stale in infostealer logs for ~7 weeks) to poison dozens of npm packages (32 Red Hat packages, 89+ packages across three waves), produced malicious packages with valid SLSA Build Level 3 provenance to evade supply-chain integrity, and added persistence targeting AI coding assistants (Claude Code, Cursor, Gemini CLI, VS Code). Tenable warns the campaign exemplifies a growing Developer-Credex
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 21eca9ca8cc2a2a28093e81cc7538f05321adac473f3a4e5640f2eca981b622f
- Enrichment time
- 2026-06-23T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.