Miasma/Mini Shai-Hulud Campaign Hits LeoPlatform npm Packages, GitHub Actions and a Go Project

· Original article ↗

Summary

Socket details a Miasma/Mini Shai-Hulud supply-chain campaign using malicious npm releases, GitHub Actions abuse, and IDE-triggered payloads in a Go project to steal developer and CI/CD secrets and spread.

Key points

  • Malicious npm releases published June 24, 2026, affected LeoPlatform and RStreams packages, along with three packages published by npm user llxlr.
  • The npm packages use a binding.gyp install-time trigger to launch obfuscated JavaScript, decrypt payloads, and run malware through Bun.
  • The payload targets developer and CI/CD secrets, including registry tokens, GitHub credentials, cloud credentials, SSH keys, and configuration files.
  • The campaign abuses GitHub Actions to collect secrets, alter repositories, upload artifacts, and potentially spread through publishing workflows.
  • A compromised Verana Blockchain Go module contains a payload triggered by a VS Code folder-open task; the observed execution path is not Go-native.
  • Socket says the investigation is ongoing and notified Verana maintainers; it recommends removing affected versions, rotating exposed secrets from clean systems, and auditing repositories and workflows.

Article Details

Attack Vectors
  • Malicious npm releases were published on June 24, 2026, through the czirker account and, for three additional packages, the llxlr account.
  • Added binding.gyp files cause npm to invoke node-gyp, whose command expansion executes a replaced index.js loader during installation without a visible preinstall or postinstall script.
  • JavaScript loaders decode shifted text, decrypt embedded AES-GCM stages, install or resolve Bun, and execute the main payload through bun run.
  • The payload collects developer and CI/CD credentials and attempts propagation through package publishing, repository modifications, and injected workflows.
  • GitHub Actions workflows collect secrets from runner context and memory and upload secret-bearing artifacts. Public reporting also describes orphan snapshot-* branches, fake dependency-update workflows, and _index.js payloads in LeoPlatform repositories.
  • In the adjacent codfish/semantic-release-action compromise, attackers force-pushed malicious commits and repointed mutable version tags, causing dependent workflows to execute attacker-controlled code.
  • Repository configuration hooks provide delayed execution when developers open repositories or start coding-agent sessions.
  • The compromised Verana source archive contains a VS Code folder-open task that executes node .claude/setup.mjs. Normal Go module resolution or builds do not appear to execute the payload.
  • The Verana archive's Claude SessionStart hook references an absent .github/setup.js file; the article treats this as a nonfunctional or leftover template, not a confirmed execution trigger.
Defensive Notes
  • Treat environments that installed affected package versions as compromised until reviewed, and preserve forensic artifacts before cleanup where possible.
  • Identify every affected developer machine, CI runner, and build container; remove compromised versions and rebuild from a known-good lockfile.
  • Rotate exposed package-registry, repository, cloud, Vault, Kubernetes, Docker, SSH, messaging-service, and CI/CD secrets from a clean machine.
  • Audit repositories for injected workflows, coding-agent hooks, folder-open tasks, .github/setup.js, _index.js, orphan branches, suspicious Dependabot-like commits, and unexplained Bun usage.
  • Review GitHub Actions runs for Bun downloads, unexpected repository creation, secret-bearing artifact uploads, and GitHub API content uploads.
  • Review pull_request_target workflows, especially those checking out pull request head code or executing untrusted build and test content.
  • Pin GitHub Actions to immutable full-length commit SHAs and monitor tag drift.
  • Restrict npm trusted publishing and GitHub OIDC permissions to workflows and branches that require them.
  • Do not limit remediation to removing malicious package versions; poisoned repository configuration can trigger execution later.

Indicators of compromise

TypeIndicatorContext
SHA256026588d39b7c650b5c0dfbba6c6fcc0e7ec8e3b72ba8639012e7f71c708f2c3bSource-listed hash of malicious index.js in leo-sdk@6.0.19.
SHA25615b415ae41df72acf1f7e9e67569531d41dee62d089d34b4c0fab0c7fe5cc14fMalicious .claude/index.js loader in the Verana source archive.
SHA2561a0e1daeaea87cab5610a3cc2aa72e7c6f1abfe55959a156368bcfa6585fa6ceDecoded first-stage JavaScript from the malicious Verana source archive.
SHA2561a3b9ed0b377f56f49b9a703612cf45e86ab7d100587e1e7a476d809fe337a8cSource-listed hash of malicious index.js in leo-aws@2.0.4.
SHA25632d1bc728d8e504952083a6adc488c309a401c7df4dc8f47b382ce32e4aebe21Source-listed hash of the malicious binding.gyp shared by the confirmed LeoPlatform/RStreams package set.
SHA2563da2ca129c9920d9acd2e3477aee8f46b5a5f0e9537ad6e7b6ab1df1007adad1Source-listed hash of the malicious leo-cli@3.0.3 npm tarball.
SHA2564a0aa78757958683155a7b9289427fb829abcad1bf5ee6399eb73e8409b0bc11Source-listed hash of package.json in the compromised leo-logger@1.0.8 release.
SHA25657ba86f6f0caaa580c1dccdf4ed7873d1470e5ea2f8e9ca7a989dc04899f13c0Malicious index.js in leo-logger@1.0.8.
SHA2566a861a479f45fe53f067091414332248bc027ffc396116811d12e57a6ff71250Source-listed hash of .claude/settings.json in the compromised Verana archive; its hook references a missing payload file.
SHA2566cb3fc3650355973b8a1ed86619a3f412fb0700f29c1c3a736cada4c2c76a9f7Source-listed shared hash of .claude/setup.mjs and .vscode/setup.mjs Bun launchers in the compromised Verana archive.
SHA256927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1fSource-listed hash of the Verana .vscode/tasks.json folder-open execution configuration.
SHA2569f93d77d32833a515bc406c46da477142bb1ac2babeecb6aa42f98669a6db015Source-listed hash of the decrypted main payload from the malicious Verana source archive.
SHA256a934a5bcf692b9d01e8129bf264be23809dfee464df471d75a9f3fa1bcede343Source-listed hash of the malicious leo-auth@4.0.6 npm tarball.
SHA256b3e217f4354e8a4383038b99b0bcaeaff191a79df58e7a1f2355a79aac2faf13Source-listed hash of the compromised verana-blockchain-v0.10.1-dev.20.zip source archive.
SHA256ceff7c51d70832c3ec8dd2744b606a23b3c924ef664ae23439b9b742ea154108Decrypted Bun bootstrap payload from the malicious Verana source archive.
SHA256df9ea0c71574e11c93141ad2f018a63a5375cd6d69ca2f744732ad7814170657Source-listed hash of malicious index.js in leo-auth@4.0.6.
SHA256f565988f281bf77bcad26ea7f543617e53da4b62f5df63d4f7a89bae1729cf81Source-listed hash of the malicious leo-sdk@6.0.19 npm tarball.
SHA256f7c47be306351ffacd46584d2067f7be676dbfe17cd89ab4880632decfe18f3dSource-listed hash of the malicious leo-aws@2.0.4 npm tarball.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationLoaders use Caesar-style shifts, AES-GCM encrypted stages, string hiding, lookup tables, and runtime string reconstruction.T1036 · MasqueradingMalicious workflows use Run Copilot and Dependabot-like naming to resemble legitimate development automation.T1059.007 · JavaScriptThe install trigger executes JavaScript loaders that use eval(), decrypt additional JavaScript, and run the main payload under Bun.T1102.001 · Dead Drop ResolverThe malicious codfish action searches GitHub commit messages for RevokeAndItGoesKaboom to retrieve operator tokens through a dead-drop channel.T1140 · Deobfuscate/Decode Files or InformationThe loader decodes shifted text and decrypts embedded AES-GCM blobs before executing later stages.T1195.001 · Compromise Software Dependencies and Development ToolsCompromised npm dependency releases and poisoned source-repository configuration introduce malware into developer and CI/CD workflows.T1518.001 · Security Software DiscoveryThe payload checks for EDR, endpoint, and fleet products including CrowdStrike, SentinelOne, Microsoft Defender, and others.T1528 · Steal Application Access TokenThe malware collects npm, PyPI, GitHub, Slack, and Twilio tokens and uses stolen publishing and repository access to spread.T1546 · Event Triggered ExecutionInjected IDE and coding-agent hooks execute payloads on repository opening, folder-open tasks, or agent session startup; the Verana sample has a confirmed VS Code folder-open path.T1552.001 · Credentials In FilesCollection logic targets .env files, Docker authentication files, Kubernetes configurations, cloud credential files, and other developer secret stores.T1552.004 · Private KeysThe payload explicitly collects SSH keys from developer environments.T1567.001 · Exfiltration to Code RepositoryThe malware stages encrypted credential exfiltration through GitHub API repository creation and content-upload paths.T1614.001 · System Language DiscoveryThe payload includes a Russian locale guard.

Malware

Products

BunThis wave combines npm registry poisoning, binding.gyp install-time execution, Bun-staged JavaScript malware, GitHub dead-drop infrastructure, GitHub Actions secret theft, AI coding assistant persistence, developer-toolClaudeIn this sample, the clearest observed trigger is a VS Code folder-open task that runs node .claude/setup.mjs; the included Claude SessionStart hook points to .github/setup.js, which is not present in thecodfish/semantic-release-actionis RevokeAndItGoesKaboom. This marker appears in the LeoPlatform/Miasma activity and in the codfish/semantic-release-action compromise documented by StepSecurity. In the codfish case, the malicious action searchedCopilotA recurring workflow template in this family is named Run Copilot. Its purpose is not to run Copilot. It is designed to blend in with AI-assisted development workflows while dumping GitHub Actions secrets into anCursorThe malware plants hooks for developer tools and coding agents, including Claude, VS Code, Cursor, Gemini, Copilot-related configuration paths, and other agent or IDE ecosystems. These hooks are designedGeminiThe malware plants hooks for developer tools and coding agents, including Claude, VS Code, Cursor, Gemini, Copilot-related configuration paths, and other agent or IDE ecosystems. These hooks are designed toGitHub ActionsLatest wave affects LeoPlatform/RStreams npm packages, three llxlr-published npm packages, the Verana Blockchain Go module, and GitHub Actions/developer-tool workflows.hexo-deployer-wrangleraccount, the activity is not limited to that publisher: three additional malicious packages, hexo-deployer-wrangler, hexo-shoka-swiper, and prism-silq, were published by the npm user llxlr.hexo-shoka-swiperis not limited to that publisher: three additional malicious packages, hexo-deployer-wrangler, hexo-shoka-swiper, and prism-silq, were published by the npm user llxlr.leo-authleo-auth@4.0.6leo-awsSocket AI Scanner’s analysis of leo-aws@2.0.4, one of the malicious packages identified in the current Miasma Mini Shai-Hulud wave, flags the compromised release as confirmed malware with multiple detections across theleo-cacheleo-cache@1.0.2leo-cdk-libleo-cdk-lib@0.0.2leo-clileo-cli@3.0.3leo-configleo-config@1.1.1leo-connector-elasticsearchleo-connector-elasticsearch@2.0.6leo-connector-mongoleo-connector-mongo@3.0.8leo-connector-mysqlleo-connector-mysql@3.0.3leo-connector-oracleleo-connector-oracle@2.0.1leo-connector-redshiftleo-connector-redshift@3.0.6leo-cronleo-cron@2.0.2leo-loggerleo-logger@1.0.8leo-sdkleo-sdk@6.0.19leo-streamsleo-streams@2.0.1LeoPlatformLatest wave affects LeoPlatform/RStreams npm packages, three llxlr-published npm packages, the Verana Blockchain Go module, and GitHub Actions/developer-tool workflows.Node.jsbun run. This continues a broader shift in the campaign toward Bun-staged malware, likely because many Node.js-focused security hooks and runtime controls do not observe Bun execution with the same depth.npmLatest wave affects LeoPlatform/RStreams npm packages, three llxlr-published npm packages, the Verana Blockchain Go module, and GitHub Actions/developer-tool workflows.prism-silqto that publisher: three additional malicious packages, hexo-deployer-wrangler, hexo-shoka-swiper, and prism-silq, were published by the npm user llxlr.RStreamsLatest wave affects LeoPlatform/RStreams npm packages, three llxlr-published npm packages, the Verana Blockchain Go module, and GitHub Actions/developer-tool workflows.rstreams-metricsrstreams-metrics@2.0.2rstreams-shard-utilrstreams-shard-util@1.0.1serverless-conventionserverless-convention@2.0.4serverless-leoserverless-leo@3.0.14solo-navsolo-nav@1.0.1Verana BlockchainLatest wave affects LeoPlatform/RStreams npm packages, three llxlr-published npm packages, the Verana Blockchain Go module, and GitHub Actions/developer-tool workflows.VS Codeis staged through source-repository configuration. In this sample, the clearest observed trigger is a VS Code folder-open task that runs node .claude/setup.mjs; the included Claude SessionStart hook points to

Tools

Related Articles