Miasma Mini Shai-Hulud Compromises 22 ImmobiliareLabs npm Package Releases

Summary
Socket reports that 22 ImmobiliareLabs Backstage npm package releases were compromised on June 26 in the Miasma Mini Shai-Hulud campaign, which uses hidden malware to steal developer and CI/CD secrets and propagate through workflows.
Key points
- Malicious releases affected 22 GitLab integration and LDAP authentication Backstage package versions under the @immobiliarelabs npm scope on June 26, 2026.
- The packages used a root-level index.js and binding.gyp build trick to execute a hidden payload without relying on preinstall or postinstall hooks.
- The multi-stage malware bootstraps Bun and targets developer and CI/CD secrets, including cloud credentials, tokens, SSH keys, and Kubernetes and Docker credentials.
- The campaign can use stolen access to modify GitHub Actions workflows, persist in IDE and AI-coding-assistant configurations, and exfiltrate data through attacker-controlled repositories.
- A compromised codfish/semantic-release-action is a possible route into release automation, but Socket says this root-cause lead is unconfirmed.
- Socket says the investigation is ongoing; teams that installed affected versions should treat those environments as compromised, review them, replace the packages, and rotate exposed credentials.
Article Details
- Attack Vectors
- Malicious releases across 22 package versions were published on 2026-06-26, including historical versions that could expose users pinned to older major releases.
- Install-time execution uses a binding.gyp command-expansion trick to invoke node index.js without preinstall or postinstall hooks.
- A root-level loader outside the apparently benign compiled entrypoint decrypts and executes a multistage payload.
- The payload steals developer and CI/CD credentials, injects workflow steps, and uses stolen access to propagate into downstream repositories.
- Persistence hooks are planted in AI coding-assistant plugins and IDE extensions.
- A compromised third-party release action is a possible upstream access path, but the source does not confirm it as the root cause.
- Deployment-triggered workflow execution can allow temporary Git objects containing attacker workflows to execute without a permanent workflow-file change on the default branch.
- Defensive Notes
- Treat environments that installed or built affected versions as compromised until reviewed; identify affected developer machines, CI runners, build containers, and developer-portal deployments.
- Remove affected releases and restore known-good package versions and lockfiles.
- Rotate exposed publishing, source-control, cloud, container, authentication, messaging, SSH, and CI/CD credentials from a clean machine.
- Review workflow runs around 2026-06-26, particularly deployment-triggered workflows, unexpected release workflows, and names resembling routine dependency maintenance.
- Audit for injected .github workflows, .github/setup.js, root-level index.js, _index.js, .gemini/settings.json, .claude hooks, .vscode tasks, and unexpected runtime installation or execution.
- Revoke or rotate long-lived maintainer and release-automation tokens; inspect publishing workflows for broad tokens and excessive permissions.
- Pin third-party actions to immutable full-length commit SHAs.
- Restrict publishing workflows to protected branches and minimize OIDC, contents, actions, and package permissions.
- Disable unnecessary deployment triggers or protect them with environment rules, branch restrictions, and actor/event allow lists.
- Hunt for unexpected binding.gyp files, large obfuscated JavaScript loaders, suspicious maintenance-themed workflow names, and the markers thebeautifulsnadsoftime, RevokeAndItGoesKaboom, and Alright Lets See If This Works.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 0574f0bee78294a5f3495144ea6e05848c5fe8dcda11414e35c65aea46ce953b | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@4.3.2. |
| SHA256 | 0ccd7c44a6352f295f65ffea21c2472566f9e73c4dd1028fe0b9971314b18de6 | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@3.0.2. |
| SHA256 | 14253cd5b8acccbbacb5cd3bb0a099fb6b0aafe4d06d032e4070b3fb814677dd | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@2.1.2. |
| SHA256 | 1623787aa0de7310a4585101212b41ae02d02801ebda5812395932392400c756 | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@4.3.2. |
| SHA256 | 1e7b04a9a4a25eb7928821a5519b0a40f7afe0f6042a6860c918b62d369096ed | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@1.0.1. |
| SHA256 | 24c578c2573bf7a04f69c4762a36a87fd32746e9db4df16b2ad92f31fbdd0d50 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@5.2.1. |
| SHA256 | 2f6cbe3a79148bc247131c36cd12689c97166a9d141dd9d9466270b4c04c3e3e | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@3.0.3. |
| SHA256 | 2ffed3b58bc267c438c759cd03b3e890904f25bacd015608f888c302741cad29 | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@4.0.2. |
| SHA256 | 333f2e3753063447819a3c86cfc475fe4bd3f0a76c05262a61c3d18b50438bb5 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3. |
| SHA256 | 3667e7080c083563f6d05118d8b08f535b391fe2a5c0f98d5bd31f96257620f7 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@2.0.5. |
| SHA256 | 3809fd3a3a912abccaa7aa201880a2cfd194ae7f9dbdc747872cd045bcb3def5 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@3.0.2. |
| SHA256 | 3b24b47a66b17d39fbdb7deccc329342b18cec6feb967adbaf80e81a70ecc609 | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@6.13.1. |
| SHA256 | 441d834d8a97b3d76bd7a9ac73174a18c1add1bf80b21319c0cb2d5737782e83 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@5.2.1. |
| SHA256 | 54086c0f23710ff45cb6bde498083d0a0098112aab9b0ef48e6e869a280f1b42 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@6.13.1. |
| SHA256 | 60099babe48a48831262b40d4c5c1dd623726060da10c1e2f74f191c9c4cd81d | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@5.2.1. |
| SHA256 | 63667208bcd2d307b307e6df43bf8960ccb7058333d00ba064ed53f180ec32ea | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@2.0.5. |
| SHA256 | 720571b83600cd61080a7779e7f44327e4df4974d4a01475439d2e59e11ab29f | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@5.2.1. |
| SHA256 | 7a879ed69a8191df5c68535f6ac41b830577b698de943c66ff40e51482d90d79 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@2.1.2. |
| SHA256 | 7bc28ba4d33d010785a5289211ad6a0d968ec0abd56201d90d74921ad83d925d | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@2.0.5. |
| SHA256 | 7cd21d65d5a085d82d07275df9a66c6dfac4e13e43ea9ef44e84a3dd14ea1b3f | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2. |
| SHA256 | 8284d9bd16c9141d331d3b724f9d57ae2cae265bf326055e18d5cde4bb5985b7 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3. |
| SHA256 | 869ffe5400477ce69bbfd5f51ddd0c40eacad9a83005956fb14787a5e1e98330 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2. |
| SHA256 | 8746d49834ad938eebeaffd380b6302c94ab0b3258268c1a8c7e57ee7d5c11e1 | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@7.0.2. |
| SHA256 | 89c218ca407c2d92359b53a9e3b7b973a761dcf323d2fa1cc2dc12c13f27afaf | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@6.13.1. |
| SHA256 | 8a71e7d9b6b1b6d3e7bee490e98b34595ceea207160fc7ed35e47f82160febbe | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@3.0.3. |
| SHA256 | 8df5d46d91589e6a3ec8d87d6eea6c71fac103f9e10dff9b88c309c1e9129b07 | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@1.1.4. |
| SHA256 | 8e83e3ece1a2a764a7c6fd78dd39cfb32cb38d22b7b3d92709cb5b87fa916403 | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@2.0.5. |
| SHA256 | 99eb789284fa62e3f956e81294247ae82f596ebf481c069ae45019ac4e879927 | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3. |
| SHA256 | 9d8ea3cefb942081a1409e842ddc541ccd65fb3e66a4f8dfe562ca8548dd09d9 | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2. |
| SHA256 | 9df6bda43678708605dfaad35f02be8027e85e6aa38193704cf192f842f0d186 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@4.0.2. |
| SHA256 | a09909e8981e17712ef38b363f94553e2f86b6c2abd6c87eada94d3d3aab937e | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@7.0.2. |
| SHA256 | a16810f972f577f129f95f147e64aa4c70977035285d357a53958496c0531223 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@5.2.1. |
| SHA256 | b38a73c365e5761fe0e7f25a391db3a264b1f2b4878a1c8cc127ba83d64e614c | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@4.3.2. |
| SHA256 | b4f90f5515df39cf346bf436e284f2dae28c9341c035765d83d82a76c86922b7 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@4.3.2. |
| SHA256 | b82f5f6f1d969ba8f32937a3d81306c631defa943b7cc7529e45a0003340ece5 | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2. |
| SHA256 | ca89ece660251554b66f1e5e9874410d206e0f080da3039e1221f1c71d817395 | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@5.2.1. |
| SHA256 | cc00c23768bee76e2f297c1766a013a681efb519888545352cff96fc5cead035 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2. |
| SHA256 | cf46348e7a4beacc0b9600c9ece3bee140f344641e90d99c741bc54507423443 | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@5.2.1. |
| SHA256 | cf5d79494d8b1fdcb5480507eee8beeb2fcd69bcd9afcdc7dc1bcdda7461913e | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@5.2.1. |
| SHA256 | d1db13a14db489531e11ccf700d7fd8701f61ad297ce02477e11acf194d3fed0 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@1.1.4. |
| SHA256 | d2aa3f9057c6f3295766aabed0a71a369353d6eb665049a45fd407fd55020fdb | Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3. |
| SHA256 | dfcdec5f43cc8d127084a2ac4d66499f13bae7f49167e3291a6f1a70738772d1 | Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@1.0.1. |
| SHA256 | ef01e18ccf618a8992ad0aa4eb7d804bbacf9f092d43d39237f283a9a289c9b9 | Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2. |
| SHA256 | ef641e956f91d501b748085996303c96a64d67f63bfeef0dda175e5aa19cca90 | Malicious binding.gyp execution artifact, byte-identical across all 22 affected packages. |
| SHA256 | ef89e81be6b9d81b9d4bc41dae5f10a7a68f33b17fd76affcf7dca2f5d50a843 | Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@6.13.1. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe root index.js loader uses Caesar-shift obfuscation and an AES-128-GCM-encrypted payload.T1036 · MasqueradingThe source describes a deployment-triggered workflow named Dependabot Updates as plausible camouflage for malicious release activity.T1059.007 · JavaScriptThe binding.gyp trigger invokes node index.js, and later JavaScript payload stages execute under Bun.T1078 · Valid AccountsStolen GitHub tokens and maintainer access are used to create repositories, modify workflows, and propagate through release automation.T1105 · Ingress Tool TransferThe execution chain downloads Bun if absent and delivers additional payload stages.T1140 · Deobfuscate/Decode Files or InformationThe root loader decrypts hidden payload material before executing subsequent stages.T1195.002 · Compromise Software Supply ChainTrusted npm packages were republished with malicious artifacts; a separately compromised release action is an unconfirmed possible upstream access path.T1528 · Steal Application Access TokenThe payload steals service tokens; StepSecurity also reported GitHub OIDC and personal access token targeting by the compromised release action.T1552.001 · Credentials In FilesThe payload steals secrets from .env files, Docker credentials, Kubernetes configurations, and other developer and CI/CD credential material.T1552.004 · Private KeysSSH keys are explicitly included among the credentials stolen by the payload.T1567.001 · Exfiltration to Code RepositoryStolen secrets are exfiltrated through the GitHub API into attacker-controlled repositories, including uploads of encrypted data.
People
Vendors
Products
@immobiliarelabs/backstage-plugin-gitlabSocket flags @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2 as part of the Miasma Mini Shai-Hulud campaign, showing that the latest release and multiple historical versions were compromised rather than a single@immobiliarelabs/backstage-plugin-gitlab-backendSocket flags @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2 as part of the Miasma Mini Shai-Hulud campaign, showing that the latest release and multiple historical versions were compromised rather than a single@immobiliarelabs/backstage-plugin-ldap-auth@immobiliarelabs/backstage-plugin-ldap-auth@1.1.4@immobiliarelabs/backstage-plugin-ldap-auth-backend@immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3BackstageLatest wave affects legitimate @immobiliarelabs Backstage packages, with malicious npm releases published across GitLab and LDAP authentication plugin families on June 26, 2026.Buntrusted developer infrastructure, publish malicious package versions, stage JavaScript malware through Bun, steal developer and CI/CD secrets, and use the stolen access to propagate further.codfish/semantic-release-actionPossible upstream compromise path: codfish/semantic-release-action#GitHub Actionsa continuation of the activity we reported yesterday involving LeoPlatform and RStreams npm packages, GitHub Actions workflow abuse, AI-agent persistence, and the Verana Go module/source-repository compromise. The newGitLabLatest wave affects legitimate @immobiliarelabs Backstage packages, with malicious npm releases published across GitLab and LDAP authentication plugin families on June 26, 2026.