Home · Briefs · CTI Daily Brief — 2026-06-27
UPDATE: Miasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages
From CTI Daily Brief — 2026-06-27 · published 2026-06-27
UPDATE (originally covered 2026-06-09): The Miasma / Mini Shai-Hulud / Hades supply-chain worm — last seen backdooring
@redhat-cloud-servicespackages and the TeamPCP "Phantom Gyp" framework — ran a fresh wave on 2026-06-24: 23+ malicious versions across the LeoPlatform and RStreams serverless-data-pipeline npm ecosystems (leo-sdk,leo-auth,leo-aws,leo-cli) after theczirkerpublisher account was compromised, plus a Go-module compromise of Verana Blockchain (Socket Security, 2026-06-25).The wave reuses the previously documented
binding.gyp/node-gypinstall-time execution to stage a Bun runtime that harvests.envfiles, npm/GitHub/cloud tokens, SSH keys and IDE/AI-agent configs, scraping GitHub Actions CI secrets (JFrog, 2026-06-26), and again carries theRevokeAndItGoesKaboomcampaign marker that Socket ties to the earliercodfish/semantic-release-actioncompromise (documented by StepSecurity), where the malicious action searched GitHub commit messages bearing that string as an operator dead-drop channel (Socket Security, 2026-06-25). Any CH/EU team consuming these packages in CI should rotate all exposed CI/cloud credentials since 2026-06-20 and alert onnode-gypevaluating JavaScript frombinding.gyp.