Skip to main content
← Back to Demos
Malware intermediate · 15 min

Miasma Worm Spread Through Poisoned Developer Packages

The Miasma worm campaign compromised 73 Microsoft-owned GitHub repositories, using a novel technique dubbed Phantom Gyp to exfiltrate credentials and propagate through six-stage infection chains that target developer environments; a Rust-based variant called IronWorm simultaneously hit the npm ecosystem. Such worms hide inside package archives and CI artifacts, executing on install and stealing tokens without raising a single alert. Detecting them demands deep inspection of the package itself, not just the filename. This demo runs the EICAR test file — the standard, completely safe detection sample — packed inside a zip archive, mimicking the delivery shape of a poisoned package. Metascan scans the archive and its contents with 30+ anti-malware engines, detects the embedded threat, and exposes it before it can reach a build pipeline or developer workstation.

Attack Technique

Worm spread via npm packages

MITRE ATT&CK

T1195.002 ↗

Platforms

linuxwindows

File Types

.txt

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---