Miasma Mini Shai-Hulud Compromises 22 ImmobiliareLabs npm Package Releases

· Original article ↗

Summary

Socket reports that 22 ImmobiliareLabs Backstage npm package releases were compromised on June 26 in the Miasma Mini Shai-Hulud campaign, which uses hidden malware to steal developer and CI/CD secrets and propagate through workflows.

Key points

  • Malicious releases affected 22 GitLab integration and LDAP authentication Backstage package versions under the @immobiliarelabs npm scope on June 26, 2026.
  • The packages used a root-level index.js and binding.gyp build trick to execute a hidden payload without relying on preinstall or postinstall hooks.
  • The multi-stage malware bootstraps Bun and targets developer and CI/CD secrets, including cloud credentials, tokens, SSH keys, and Kubernetes and Docker credentials.
  • The campaign can use stolen access to modify GitHub Actions workflows, persist in IDE and AI-coding-assistant configurations, and exfiltrate data through attacker-controlled repositories.
  • A compromised codfish/semantic-release-action is a possible route into release automation, but Socket says this root-cause lead is unconfirmed.
  • Socket says the investigation is ongoing; teams that installed affected versions should treat those environments as compromised, review them, replace the packages, and rotate exposed credentials.

Article Details

Attack Vectors
  • Malicious releases across 22 package versions were published on 2026-06-26, including historical versions that could expose users pinned to older major releases.
  • Install-time execution uses a binding.gyp command-expansion trick to invoke node index.js without preinstall or postinstall hooks.
  • A root-level loader outside the apparently benign compiled entrypoint decrypts and executes a multistage payload.
  • The payload steals developer and CI/CD credentials, injects workflow steps, and uses stolen access to propagate into downstream repositories.
  • Persistence hooks are planted in AI coding-assistant plugins and IDE extensions.
  • A compromised third-party release action is a possible upstream access path, but the source does not confirm it as the root cause.
  • Deployment-triggered workflow execution can allow temporary Git objects containing attacker workflows to execute without a permanent workflow-file change on the default branch.
Defensive Notes
  • Treat environments that installed or built affected versions as compromised until reviewed; identify affected developer machines, CI runners, build containers, and developer-portal deployments.
  • Remove affected releases and restore known-good package versions and lockfiles.
  • Rotate exposed publishing, source-control, cloud, container, authentication, messaging, SSH, and CI/CD credentials from a clean machine.
  • Review workflow runs around 2026-06-26, particularly deployment-triggered workflows, unexpected release workflows, and names resembling routine dependency maintenance.
  • Audit for injected .github workflows, .github/setup.js, root-level index.js, _index.js, .gemini/settings.json, .claude hooks, .vscode tasks, and unexpected runtime installation or execution.
  • Revoke or rotate long-lived maintainer and release-automation tokens; inspect publishing workflows for broad tokens and excessive permissions.
  • Pin third-party actions to immutable full-length commit SHAs.
  • Restrict publishing workflows to protected branches and minimize OIDC, contents, actions, and package permissions.
  • Disable unnecessary deployment triggers or protect them with environment rules, branch restrictions, and actor/event allow lists.
  • Hunt for unexpected binding.gyp files, large obfuscated JavaScript loaders, suspicious maintenance-themed workflow names, and the markers thebeautifulsnadsoftime, RevokeAndItGoesKaboom, and Alright Lets See If This Works.

Indicators of compromise

TypeIndicatorContext
SHA2560574f0bee78294a5f3495144ea6e05848c5fe8dcda11414e35c65aea46ce953bMalicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@4.3.2.
SHA2560ccd7c44a6352f295f65ffea21c2472566f9e73c4dd1028fe0b9971314b18de6Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@3.0.2.
SHA25614253cd5b8acccbbacb5cd3bb0a099fb6b0aafe4d06d032e4070b3fb814677ddMalicious index.js in @immobiliarelabs/backstage-plugin-gitlab@2.1.2.
SHA2561623787aa0de7310a4585101212b41ae02d02801ebda5812395932392400c756Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@4.3.2.
SHA2561e7b04a9a4a25eb7928821a5519b0a40f7afe0f6042a6860c918b62d369096edMalicious index.js in @immobiliarelabs/backstage-plugin-gitlab@1.0.1.
SHA25624c578c2573bf7a04f69c4762a36a87fd32746e9db4df16b2ad92f31fbdd0d50Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@5.2.1.
SHA2562f6cbe3a79148bc247131c36cd12689c97166a9d141dd9d9466270b4c04c3e3eCompromised tarball for @immobiliarelabs/backstage-plugin-gitlab@3.0.3.
SHA2562ffed3b58bc267c438c759cd03b3e890904f25bacd015608f888c302741cad29Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@4.0.2.
SHA256333f2e3753063447819a3c86cfc475fe4bd3f0a76c05262a61c3d18b50438bb5Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3.
SHA2563667e7080c083563f6d05118d8b08f535b391fe2a5c0f98d5bd31f96257620f7Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@2.0.5.
SHA2563809fd3a3a912abccaa7aa201880a2cfd194ae7f9dbdc747872cd045bcb3def5Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@3.0.2.
SHA2563b24b47a66b17d39fbdb7deccc329342b18cec6feb967adbaf80e81a70ecc609Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@6.13.1.
SHA256441d834d8a97b3d76bd7a9ac73174a18c1add1bf80b21319c0cb2d5737782e83Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@5.2.1.
SHA25654086c0f23710ff45cb6bde498083d0a0098112aab9b0ef48e6e869a280f1b42Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@6.13.1.
SHA25660099babe48a48831262b40d4c5c1dd623726060da10c1e2f74f191c9c4cd81dMalicious index.js in @immobiliarelabs/backstage-plugin-gitlab@5.2.1.
SHA25663667208bcd2d307b307e6df43bf8960ccb7058333d00ba064ed53f180ec32eaMalicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@2.0.5.
SHA256720571b83600cd61080a7779e7f44327e4df4974d4a01475439d2e59e11ab29fCompromised tarball for @immobiliarelabs/backstage-plugin-gitlab@5.2.1.
SHA2567a879ed69a8191df5c68535f6ac41b830577b698de943c66ff40e51482d90d79Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@2.1.2.
SHA2567bc28ba4d33d010785a5289211ad6a0d968ec0abd56201d90d74921ad83d925dCompromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@2.0.5.
SHA2567cd21d65d5a085d82d07275df9a66c6dfac4e13e43ea9ef44e84a3dd14ea1b3fMalicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2.
SHA2568284d9bd16c9141d331d3b724f9d57ae2cae265bf326055e18d5cde4bb5985b7Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3.
SHA256869ffe5400477ce69bbfd5f51ddd0c40eacad9a83005956fb14787a5e1e98330Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2.
SHA2568746d49834ad938eebeaffd380b6302c94ab0b3258268c1a8c7e57ee7d5c11e1Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab@7.0.2.
SHA25689c218ca407c2d92359b53a9e3b7b973a761dcf323d2fa1cc2dc12c13f27afafCompromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@6.13.1.
SHA2568a71e7d9b6b1b6d3e7bee490e98b34595ceea207160fc7ed35e47f82160febbeMalicious index.js in @immobiliarelabs/backstage-plugin-gitlab@3.0.3.
SHA2568df5d46d91589e6a3ec8d87d6eea6c71fac103f9e10dff9b88c309c1e9129b07Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@1.1.4.
SHA2568e83e3ece1a2a764a7c6fd78dd39cfb32cb38d22b7b3d92709cb5b87fa916403Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@2.0.5.
SHA25699eb789284fa62e3f956e81294247ae82f596ebf481c069ae45019ac4e879927Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3.
SHA2569d8ea3cefb942081a1409e842ddc541ccd65fb3e66a4f8dfe562ca8548dd09d9Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2.
SHA2569df6bda43678708605dfaad35f02be8027e85e6aa38193704cf192f842f0d186Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@4.0.2.
SHA256a09909e8981e17712ef38b363f94553e2f86b6c2abd6c87eada94d3d3aab937eCompromised tarball for @immobiliarelabs/backstage-plugin-gitlab@7.0.2.
SHA256a16810f972f577f129f95f147e64aa4c70977035285d357a53958496c0531223Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@5.2.1.
SHA256b38a73c365e5761fe0e7f25a391db3a264b1f2b4878a1c8cc127ba83d64e614cCompromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@4.3.2.
SHA256b4f90f5515df39cf346bf436e284f2dae28c9341c035765d83d82a76c86922b7Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@4.3.2.
SHA256b82f5f6f1d969ba8f32937a3d81306c631defa943b7cc7529e45a0003340ece5Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2.
SHA256ca89ece660251554b66f1e5e9874410d206e0f080da3039e1221f1c71d817395Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@5.2.1.
SHA256cc00c23768bee76e2f297c1766a013a681efb519888545352cff96fc5cead035Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2.
SHA256cf46348e7a4beacc0b9600c9ece3bee140f344641e90d99c741bc54507423443Malicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth@5.2.1.
SHA256cf5d79494d8b1fdcb5480507eee8beeb2fcd69bcd9afcdc7dc1bcdda7461913eMalicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@5.2.1.
SHA256d1db13a14db489531e11ccf700d7fd8701f61ad297ce02477e11acf194d3fed0Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth@1.1.4.
SHA256d2aa3f9057c6f3295766aabed0a71a369353d6eb665049a45fd407fd55020fdbMalicious index.js in @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3.
SHA256dfcdec5f43cc8d127084a2ac4d66499f13bae7f49167e3291a6f1a70738772d1Compromised tarball for @immobiliarelabs/backstage-plugin-gitlab@1.0.1.
SHA256ef01e18ccf618a8992ad0aa4eb7d804bbacf9f092d43d39237f283a9a289c9b9Compromised tarball for @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2.
SHA256ef641e956f91d501b748085996303c96a64d67f63bfeef0dda175e5aa19cca90Malicious binding.gyp execution artifact, byte-identical across all 22 affected packages.
SHA256ef89e81be6b9d81b9d4bc41dae5f10a7a68f33b17fd76affcf7dca2f5d50a843Malicious index.js in @immobiliarelabs/backstage-plugin-gitlab-backend@6.13.1.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe root index.js loader uses Caesar-shift obfuscation and an AES-128-GCM-encrypted payload.T1036 · MasqueradingThe source describes a deployment-triggered workflow named Dependabot Updates as plausible camouflage for malicious release activity.T1059.007 · JavaScriptThe binding.gyp trigger invokes node index.js, and later JavaScript payload stages execute under Bun.T1078 · Valid AccountsStolen GitHub tokens and maintainer access are used to create repositories, modify workflows, and propagate through release automation.T1105 · Ingress Tool TransferThe execution chain downloads Bun if absent and delivers additional payload stages.T1140 · Deobfuscate/Decode Files or InformationThe root loader decrypts hidden payload material before executing subsequent stages.T1195.002 · Compromise Software Supply ChainTrusted npm packages were republished with malicious artifacts; a separately compromised release action is an unconfirmed possible upstream access path.T1528 · Steal Application Access TokenThe payload steals service tokens; StepSecurity also reported GitHub OIDC and personal access token targeting by the compromised release action.T1552.001 · Credentials In FilesThe payload steals secrets from .env files, Docker credentials, Kubernetes configurations, and other developer and CI/CD credential material.T1552.004 · Private KeysSSH keys are explicitly included among the credentials stolen by the payload.T1567.001 · Exfiltration to Code RepositoryStolen secrets are exfiltrated through the GitHub API into attacker-controlled repositories, including uploads of encrypted data.

People

Vendors

Products

@immobiliarelabs/backstage-plugin-gitlabSocket flags @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2 as part of the Miasma Mini Shai-Hulud campaign, showing that the latest release and multiple historical versions were compromised rather than a single@immobiliarelabs/backstage-plugin-gitlab-backendSocket flags @immobiliarelabs/backstage-plugin-gitlab-backend@7.0.2 as part of the Miasma Mini Shai-Hulud campaign, showing that the latest release and multiple historical versions were compromised rather than a single@immobiliarelabs/backstage-plugin-ldap-auth@immobiliarelabs/backstage-plugin-ldap-auth@1.1.4@immobiliarelabs/backstage-plugin-ldap-auth-backend@immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3BackstageLatest wave affects legitimate @immobiliarelabs Backstage packages, with malicious npm releases published across GitLab and LDAP authentication plugin families on June 26, 2026.Buntrusted developer infrastructure, publish malicious package versions, stage JavaScript malware through Bun, steal developer and CI/CD secrets, and use the stolen access to propagate further.codfish/semantic-release-actionPossible upstream compromise path: codfish/semantic-release-action#GitHub Actionsa continuation of the activity we reported yesterday involving LeoPlatform and RStreams npm packages, GitHub Actions workflow abuse, AI-agent persistence, and the Verana Go module/source-repository compromise. The newGitLabLatest wave affects legitimate @immobiliarelabs Backstage packages, with malicious npm releases published across GitLab and LDAP authentication plugin families on June 26, 2026.

Countries

Industries

Related Articles