What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials

2026-06-23T20:52:18Z21eca9ca8cc2a2a28093e81cc7538f05321adac473f3a4e5640f2eca981b622f
ai-coding-assistantscisa-bod-26-04ctemdeveloper-credential-economydeveloper-credentialsinfostealermiasmamicrosoft-patch-tuesdaymini-shai-huludnpmoracle-cspupersistencepoisoned-packagesprovenance-bypassred-hatslsasupply-chainvulnerability-managementwormzero-day

What happened

This feed aggregates June 2026 Tenable analysis and advisories: a novel supply-chain campaign (“Miasma”)—a self-propagating npm worm derived from Mini Shai-Hulud—leveraged a stolen developer session cookie (stale in infostealer logs for ~7 weeks) to poison dozens of npm packages (32 Red Hat packages, 89+ packages across three waves), produced malicious packages with valid SLSA Build Level 3 provenance to evade supply-chain integrity, and added persistence targeting AI coding assistants (Claude Code, Cursor, Gemini CLI, VS Code). Tenable warns the campaign exemplifies a growing Developer-Credex

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
21eca9ca8cc2a2a28093e81cc7538f05321adac473f3a4e5640f2eca981b622f
Enrichment time
2026-06-23T20:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.