The OpenSourceMalware Show
The OpenSourceMalware Show

Miasma npm worm hits Red Hat, new OpenSourceMalware research on 2026 trends, the Moika campaign

04 June 2026 40:53 OpenSourceMalware

Listen to episode

About this episode

This week Paul and Jenn talk about:

  • Miasma Campaign — Starting June 1st with 32 Red Hat @redhat-cloud-services packages (averaging 80,000 weekly downloads) compromised, the campaign expanded to over 80 packages and 286+ malicious versions within days. The worm is the first confirmed in-the-wild use of TeamPCP's open-sourced MiniShai Hulud worm, though TeamPCP has not claimed credit. It is multi-ecosystem (npm, PyPI, RubyGems) and the Ruby variant appears to be LLM-translated, not part of the original open-sourced code. The initial Red Hat compromise came not through a GitHub Actions vulnerability but through abused gaps in npm trusted publishing. A live comment from Francois (VP of Security Research at BoostSecurity) corrected this in real time during the show.
  • The Shift from Human to Machine Attack Paths — Account takeover attacks have shifted away from social engineering as the primary foothold. The Axios compromise in early 2026 was likely the last major example of a social-engineering-based entry point. Threat actors now primarily target CI pipelines, automated builds, and developer tooling. Automation has also accelerated post-compromise activity: credential abuse now begins within seconds of a system being popped, rather than requiring manual follow-through.
  • OpenSourceMalware Data Trends (Jan to mid-May 2026) — Three trends from six months of OSM threat report data. First, npm remains the dominant ecosystem by volume but PyPI is growing at a comparable rate and the two frequently correlate, reflecting multi-ecosystem attack campaigns. Second, the vast majority of malicious packages have fewer than 10,000 weekly downloads (indicative of typosquatting and dependency confusion), but the share of high-download packages has grown over the period, with account takeovers representing 60 to 65% of new records in the week of May 11th. Third, malicious ClawHub skills have grown rapidly since January, with over 700 in the database by end of March. Nearly a fifth target marketing roles (SEO, Klaviyo, TikTok, YouTube), reflecting threat actors going after non-developer users of AI tools.
  • Moika Campaign — Over 260 verified threat reports tied to infrastructure at oob.moika.tech, with nearly 300 packages deployed. The campaign sits in a gray area: the account has a history consistent with bug bounty research (PoCs, packages without payloads, version numbering at 99.9 to float above legitimate packages), but the payloads on others are overtly credential-stealing and one researcher has attributed the campaign to a Russian nexus. This connects to a broader conversation about the volume of security-researcher->

Resources

  • OpenSourceMalware threat reports for Miasma
  • (blog) Miasma: Supply Chain Attack Targeting RedHat npm Packages
  • (blog) Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
  • (blog) Trusted Publishing, Untrusted Branch: Red Hat npm
  • (blog) The Software Supply Chain Malware Landscape: January - May 2026
  • OpenSourceMalware threat records for Moika 
  • (blog) 183 npm Packages Target Cloud and Finance via oob.moika.tech

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 The OpenSourceMalware Show. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.